Skip to main content

Posts

Showing posts with the label pattern

Dropnote 2 Pony changing its pattern

Dropnote 2 Pony changing its pattern After the tweet from @malware_traffic I found myself recognizing the callback pattern and thought I would take a look. #CryptoWall infection - 2014-05-25 - Angler EK from 192.99.41.165 - denoting.centrixsf[.]com - PCAP/malware/more at: http://t.co/LdEKOD3q0n � Brad (@malware_traffic) May 25, 2014 The initial callback after the successful exploitation was a POST-request to gate.php togheter with a few GET-requests for executables, both using HTTP/1.0 as shown below: The first pattern looks alot like Pony (Pony is well documented on other blogs), however, I was expecting the usual "Microsoft 98" user-agent when inspecting the whole request, but instead I found: Looking at Virustotal results, which at the time of writing is 3/52, its flagged as "Fareit" by ESET and Kaspersky. So now to the interesting part, what is this Pony up to? Pony itself is normally around 86kb depending on configuration and the payload itself in this case i...