hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.015 Compression |
MalwarePony | Pony attachments have been delivered via compressed archive files. |
| T1027.016 Junk Code Insertion |
MalwarePony | Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult. |
| T1036 Masquerading |
MalwarePony | Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy. |
| T1059.003 Windows Command Shell |
MalwarePony | Pony has used batch scripts to delete itself after execution. |
| T1070.004 File Deletion |
MalwarePony | Pony has used scripts to delete itself after execution. |
| T1071.001 Web Protocols |
MalwarePony | Pony has sent collected information to the C2 via HTTP POST request. |
| T1082 System Information Discovery |
MalwarePony | Pony has collected the Service Pack, language, and region information to send to the C2. |
| T1087.001 Local Account |
MalwarePony | Pony has used the |
| T1105 Ingress Tool Transfer |
MalwarePony | Pony can download additional files onto the infected system. |
| T1106 Native API |
MalwarePony | Pony has used several Windows functions for various purposes. |
| T1110.001 Password Guessing |
MalwarePony | Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| T1204.001 Malicious Link |
MalwarePony | Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks. |
| T1204.002 Malicious File |
MalwarePony | Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format). |
| T1497.003 Time Based Checks |
MalwarePony | Pony has delayed execution using a built-in function to avoid detection and analysis. |
| T1566.001 Spearphishing Attachment |
MalwarePony | Pony has been delivered via spearphishing attachments. |
| T1566.002 Spearphishing Link |
MalwarePony | Pony has been delivered via spearphishing emails which contained malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.