{"id":1098,"date":"2018-04-21T03:31:27","date_gmt":"2018-04-21T02:31:27","guid":{"rendered":"http:\/\/www.herbiez.com\/?p=1098"},"modified":"2018-04-21T03:31:27","modified_gmt":"2018-04-21T02:31:27","slug":"2018-04-20-pony-fareit-malspam","status":"publish","type":"post","link":"https:\/\/www.herbiez.com\/?p=1098","title":{"rendered":"2018-04-20 Pony\/Fareit Malspam"},"content":{"rendered":"<p>Found some malspam that looks to be Pony\/Fareit related. Generally speaking, Pony\/Fareit deals with credential stealing varying from FTP to email clients and any other credential that it may be able to obtain. The results that I got from my VM are different than what I got from Any.Run and Payload Security. For example, on my VM it did not reach out to &#8220;myrfrers[.]com&#8221; domain, nor did the Any.Run sample try to reach out to the &#8220;pornhouse[.]mobi&#8221; domain. I also did not see anything from the limited run of ProcMon relating to any FTP sites, or anything trying to obtain credentials. Makes me wonder if this was, possibly, VM aware perhaps. Anyways&#8230;<\/p>\n<p>The artifacts from this investigation can be found over at my Github repo located <a href=\"http:\/\/github.com\/bloomer1016\/2018-04-20-Pony-Fareit-Malspam\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/email.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/email.png\" alt=\"\" width=\"763\" height=\"836\" class=\"aligncenter size-full wp-image-1099\" \/><\/a><\/p>\n<p>IOCs:<br \/>\n=====<br \/>\n67[.]227.226[.]240 \/ pornhouse[.]mobi (GET \/main.php?dir=\/\/Virgin%20Babes%20First%20Sex&amp;start=1&amp;sort=1 HTTP\/1.0)<\/p>\n<p>Artifacts:<br \/>\n==========<br \/>\nFile name: DHL_AWB invoice.ace<br \/>\nFile size: 361KB<br \/>\nFile path: NA<br \/>\nMD5 hash: 1a8b1c6a01679c78b0bb0ec701a17299<br \/>\nVirustotal: <a href=\"http:\/\/www.virustotal.com\/#\/file\/3b04d16d9bdad64afd5acfeca0e94d228ba481d00535ba9622daa111d81fa20b\/detection\" rel=\"noopener\" target=\"_blank\">http:\/\/www.virustotal.com\/#\/file\/3b04d16d9bdad64afd5acfeca0e94d228ba481d00535ba9622daa111d81fa20b\/detection<\/a><br \/>\nDetection ratio: 2 \/ 59<br \/>\nFirst Detected: 2018-04-20 11:02:07<br \/>\nHybrid Analysis: NA<\/p>\n<p>File name: DHL_AWB invoice.scr<br \/>\nFile size: 830KB<br \/>\nFile path: NA<br \/>\nMD5 hash: 2df397766a1d4c2cfc0878d0f06e017c<br \/>\nVirustotal: NA<br \/>\nHybrid Analysis: <a href=\"http:\/\/www.hybrid-analysis.com\/sample\/0161db0f1201509c9a5ab91ce20974f4d239a3d55915fd81e39177835f2af623?environmentId=100\" rel=\"noopener\" target=\"_blank\">http:\/\/www.hybrid-analysis.com\/sample\/0161db0f1201509c9a5ab91ce20974f4d239a3d55915fd81e39177835f2af623?environmentId=100<\/a><br \/>\nAny.Run: <a href=\"http:\/\/app.any.run\/tasks\/f798e581-cfb9-4225-866f-48870e8db8de\" rel=\"noopener\" target=\"_blank\">http:\/\/app.any.run\/tasks\/f798e581-cfb9-4225-866f-48870e8db8de<\/a><\/p>\n<p>File name: 2207875.bat<br \/>\nFile size: 94B<br \/>\nFile path: C:\\Users\\%username%\\AppData\\Local\\Temp<br \/>\nMD5 hash: 3880eeb1c736d853eb13b44898b718ab<br \/>\nVirustotal: <a href=\"http:\/\/www.virustotal.com\/#\/file\/936d9411d5226b7c5a150ecaf422987590a8870c8e095e1caa072273041a86e7\/detection\" rel=\"noopener\" target=\"_blank\">http:\/\/www.virustotal.com\/#\/file\/936d9411d5226b7c5a150ecaf422987590a8870c8e095e1caa072273041a86e7\/detection<\/a><br \/>\nDetection ratio: 26 \/ 60<br \/>\nFirst Detected: 2012-12-18 22:56:31<br \/>\nHybrid Analysis: <a href=\"http:\/\/www.hybrid-analysis.com\/search?query=3880eeb1c736d853eb13b44898b718ab\" rel=\"noopener\" target=\"_blank\">http:\/\/www.hybrid-analysis.com\/search?query=3880eeb1c736d853eb13b44898b718ab<\/a><\/p>\n<p>Analysis:<br \/>\n=========<br \/>\nThis was a simple infection that stemed from extracting out the malicious screensaver file from the ACE archive. Once the malicious screensaver was ran, less than a minute later went by and the process terminated itself while starting up some child processes (process hollowing). Once the malware took foot, what I saw was the screensaver run, then terminate, while then creating a new thread for &#8220;cmd.exe&#8221; as seen below.<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/proceess-tree.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/proceess-tree.png\" alt=\"\" width=\"1286\" height=\"92\" class=\"aligncenter size-full wp-image-1101\" \/><\/a><\/p>\n<p>Once the &#8220;cmd.exe&#8221; process had started, I noticed that there was a new  file in the %TEMP% folder as well. The following is a cleaned up version of one of the batch files creeated.<\/p>\n<pre class=\"brush: vb; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\n:ktk   \r\ndel %1  \r\nif exist %1 goto \t\r\nktk\r\ndel %0<\/pre>\n<p>Timing the creation of the batch files with the PCAP, it looks like it may have been reaching out to the &#8220;pornhouse[.]mobi&#8221; site at the same time. <\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/pcap.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/pcap.png\" alt=\"\" width=\"1678\" height=\"660\" class=\"aligncenter size-full wp-image-1100\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/tcp_stream.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/04\/tcp_stream.png\" alt=\"\" width=\"548\" height=\"292\" class=\"aligncenter size-full wp-image-1102\" \/><\/a><\/p>\n<p>Letting this run for a bit, the same pattern continued with several of the same batch files, albeit random names, being created.<\/p>\n<p>The interesting thing with this one was the fact that I could not run anything from SysInternals on my VM. If I ran either ProcMon or Process Explorer and then executed the malware, the binary would spawn a new process and then terminate quickjly afterwards. If I executed the malware and then started ProcMon, or Process Explorer after the fact, the malware would run for a while and then terminate.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Found some malspam that looks to be Pony\/Fareit related. Generally speaking, Pony\/Fareit deals with credential stealing varying from FTP to email clients and any other credential that it may be able to obtain. The results that I got from my VM are different than what I got from Any.Run and Payload Security. For example, on my VM it did not reach out to &#8220;myrfrers[.]com&#8221; domain, nor did the Any.Run sample try to reach out to the &#8220;pornhouse[.]mobi&#8221; domain. I also did not see anything from the limited run of ProcMon relating to any FTP sites, or anything trying to obtain&#8230;<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/www.herbiez.com\/?p=1098\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[23,22],"class_list":["post-1098","post","type-post","status-publish","format-standard","hentry","category-packet-analysis","tag-fareit","tag-pony"],"_links":{"self":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1098","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1098"}],"version-history":[{"count":3,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1098\/revisions"}],"predecessor-version":[{"id":1105,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1098\/revisions\/1105"}],"wp:attachment":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1098"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1098"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}