s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870 high

📛 Threat Title

Pony: A06194A36273470E5BEDEBE9D313B951.exe

Category: Pony Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 87040 bytes. Tags: exe, Pony. Reporter: abuse_ch. First seen: 2026-08-04 21:45:06.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 6d809cf712ffd89f86be8f79e3bcd47d

IOC database

Type
hash_imphash
Value
6d809cf712ffd89f86be8f79e3bcd47d
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870

IOC database

Type
hash_sha256
Value
93cfcf58ba02b6704041d8e036b4230a4ba9561723c5e7e8fdce681684864870
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Pony

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 a21226a0e754f7f27579c17e4f1f35ed7a1d978e

IOC database

Type
hash_sha1
Value
a21226a0e754f7f27579c17e4f1f35ed7a1d978e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 a06194a36273470e5bedebe9d313b951

IOC database

Type
hash_md5
Value
a06194a36273470e5bedebe9d313b951
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 87040 bytes. Tags: exe, Pony. Reporter: abuse_ch. First seen: 2026-08-04 21:45:06.

Remediations (10)

  • web:any.run

    Pony , also known as Fareit, is an information stealer and loader - a malware used to collect data from infected machines and install other malicious programs. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc.

  • web:attack.mitre.org

    Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.

  • web:gamesmylittlepony.com

    We would like to show you a description here but the site won't allow us.

  • web:poniverse.net

    Poniverse is the supercommunity that runs multiple brony fan sites. We offer multiple things a stand-alone site cannot: one universal login for every Poniverse site, global notifications from every site collected in a central dashboard, cross-site integration wherever it makes sense, and dedicated servers that stay online under heavy traffic.

  • web:strawberryreef.com

    Welcome to Strawberry Reef's My Little Pony Reference Guide... now for all generations! I am excited to share my passion for these beautiful little ponies with you. I am a detail nut, and have been researching My Little Pony , specifically the third generation (G3) since 2006. This site is a fan site to be used for informational purposes only. This site is in no way affiliated with Hasbro, Inc ...

  • web:www.cyberark.com

    Mitigation As this article shows, Pony is still active and is getting trickier and trickier. Although the main payload is clearly the famous Pony Loader version 2.0, malware's encapsulation and obfuscation continues to get more complex and it's a much bigger challenge for both protection software and security analyzers to deal with.

  • web:www.malwarebytes.com

    Spyware. Pony is Malwarebytes' detection name for a Remote Access Trojan (RAT) application that may run in the background and silently collect information about the system, connected users, and network activity.

  • web:www.pcrisk.com

    Pony shares similarities with FormBook, Adwind, and dozens of other viruses. Following infiltration, the malware starts gathering sensitive information and sending it to the developers/distributors (cyber criminals). These people then attempt to misuse received data in any possible way to generate as much revenue as possible.

  • web:www.youtube.com

    Welcome to the magical world of My Little Pony , where friendship, adventure, and wonder are always just a sparkle away! 🦄 Join Twilight Sparkle, Rainbow Dash, and all your favorite ponies as ...

  • web:www.youtube.com

    Welcome to the enchanting world of My Little Pony : Friendship is Magic! 🦄 Join Twilight Sparkle, Rainbow Dash, Pinkie Pie, Applejack, Rarity, and Fluttershy as they embark on thrilling ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.