s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868531 high

📛 Threat Title

Pony: URL that is used for botnet Command&control (C&C) http://mainserver.com/gate.php

Category: Pony Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Pony (aliases: Siplog,Fareit). Confidence: 100. First seen: 2026-08-04 21:45:03 UTC. Reporter: abuse_ch. Tags: Pony.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://mainserver.com/gate.php UrlVoid 4 / 35

IOC database

Type
url
Value
http://mainserver.com/gate.php
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Pony

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Pony (aliases: Siplog,Fareit). Confidence: 100. First seen: 2026-08-04 21:45:03 UTC. Reporter: abuse_ch. Tags: Pony.

Remediations (10)

  • web:any.run

    Pony , also known as Fareit, is an information stealer and loader - a malware used to collect data from infected machines and install other malicious programs. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc.

  • web:attack.mitre.org

    Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.

  • web:cyberint.com

    Diverging from the typical botnet structure, Pony stealer does not rely on a centralized Command and Control (C&C) server or a network of such servers for executing its attacks.

  • web:dl.acm.org

    The latest innovation step addresses one of the main Archilles' heels in malware operations: the resilient addressing of the command & control (C&C) server. As domain blacklisting and DGA reversing have become mature security practices, malware authors are now turning to the Bitcoin blockchain, and use its resilient design principle to disseminate control information that cannot be removed by ...

  • web:threatfox.abuse.ch

    Malware Samples The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

  • web:www.acunetix.com

    It features a control panel, database and user management, logging and also statistics, which can be used to build and control its botnets . Once a computer is infected, Pony runs in the background collecting information about the system, its network activity and the users that are connected to it.

  • web:www.enigmasoftware.com

    The Pony botnet is a very large botnet that was uncovered recently, in the Summer of 2013. The Pony botnet is similar to some of the most common botnets active today. The Pony botnet controller includes a control panel and advanced features that allow the criminals controlling the Pony botnet to gather data, keep records and statistics and control the botnet effectively from a single location ...

  • web:www.netskope.com

    Pony malware steals user data and is often used in phishing campaigns in SaaS accounts. Learn how to protect your accounts from pony malware.

  • web:www.spamhaus.org

    About the Data The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Get the latest insights on the botnet command and controllers ( C&Cs ) our researchers are observing, including geolocation and who is hosting them. Access the full report here.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.