MB-93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870
high
📛 Threat Title
Pony: A06194A36273470E5BEDEBE9D313B951.exe
Description
File type: exe. Size: 87040 bytes. Tags: exe, Pony. Reporter: abuse_ch. First seen: 2026-08-04 21:45:06.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
6d809cf712ffd89f86be8f79e3bcd47d
IOC database
- Type
- hash_imphash
- Value
6d809cf712ffd89f86be8f79e3bcd47d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870
IOC database
- Type
- hash_sha256
- Value
93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Pony
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
a21226a0e754f7f27579c17e4f1f35ed7a1d978e
IOC database
- Type
- hash_sha1
- Value
a21226a0e754f7f27579c17e4f1f35ed7a1d978e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
a06194a36273470e5bedebe9d313b951
IOC database
- Type
- hash_md5
- Value
a06194a36273470e5bedebe9d313b951- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 87040 bytes. Tags: exe, Pony. Reporter: abuse_ch. First seen: 2026-08-04 21:45:06.
Remediations (10)
-
web:any.run
Pony , also known as Fareit, is an information stealer and loader - a malware used to collect data from infected machines and install other malicious programs. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc.
-
web:attack.mitre.org
Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.
-
web:gamesmylittlepony.com
We would like to show you a description here but the site won't allow us.
-
web:poniverse.net
Poniverse is the supercommunity that runs multiple brony fan sites. We offer multiple things a stand-alone site cannot: one universal login for every Poniverse site, global notifications from every site collected in a central dashboard, cross-site integration wherever it makes sense, and dedicated servers that stay online under heavy traffic.
-
web:strawberryreef.com
Welcome to Strawberry Reef's My Little Pony Reference Guide... now for all generations! I am excited to share my passion for these beautiful little ponies with you. I am a detail nut, and have been researching My Little Pony , specifically the third generation (G3) since 2006. This site is a fan site to be used for informational purposes only. This site is in no way affiliated with Hasbro, Inc ...
-
web:www.cyberark.com
Mitigation As this article shows, Pony is still active and is getting trickier and trickier. Although the main payload is clearly the famous Pony Loader version 2.0, malware's encapsulation and obfuscation continues to get more complex and it's a much bigger challenge for both protection software and security analyzers to deal with.
-
web:www.malwarebytes.com
Spyware. Pony is Malwarebytes' detection name for a Remote Access Trojan (RAT) application that may run in the background and silently collect information about the system, connected users, and network activity.
-
web:www.pcrisk.com
Pony shares similarities with FormBook, Adwind, and dozens of other viruses. Following infiltration, the malware starts gathering sensitive information and sending it to the developers/distributors (cyber criminals). These people then attempt to misuse received data in any possible way to generate as much revenue as possible.
-
web:www.youtube.com
Welcome to the magical world of My Little Pony , where friendship, adventure, and wonder are always just a sparkle away! 🦄 Join Twilight Sparkle, Rainbow Dash, and all your favorite ponies as ...
-
web:www.youtube.com
Welcome to the enchanting world of My Little Pony : Friendship is Magic! 🦄 Join Twilight Sparkle, Rainbow Dash, Pinkie Pie, Applejack, Rarity, and Fluttershy as they embark on thrilling ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.