13 Years of Service
24%





Purpose and Objectives of this project
-Collecting FTP / HTTP passwords from 95 + popular FTP-client and Web-browser from infected computers.
-Collecting E-mail password (POP3, IMAP, SMTP).
-Collecting signing certificates of executable files and drivers.
-Collect RDP(Remote Desktop Connection) passwords.
-Invisible to the user's application.
-Minimum amount of work and time grabber on the infected computer.
Collect passwords from your computer and send them to c&c panel.
Works on all versions of Windows, from Win98 to Windows 8(including windows server) - x86 and x64.
Implemented instantaneous decoding for saved passwords for the following programs:
Builder coded in delphi XE2, stub coded in asm(32 kb compressed).System InfoFAR Manager
Total Commander
WS_FTP
CuteFTP
FlashFXP
FileZilla
FTP Commander
BulletProof FTP
SmartFTP
TurboFTP
FFFTP
CoffeeCup FTP / Sitemapper
CoreFTP
FTP Explorer
Frigate3 FTP
SecureFX
UltraFXP
FTPRush
WebSitePublisher
BitKinex
ExpanDrive
ClassicFTP
Fling
SoftX
Directory Opus
FreeFTP / DirectFTP
LeapFTP
WinSCP
32bit FTP
NetDrive
WebDrive
FTP Control
Opera
WiseFTP
FTP Voyager
Firefox
FireFTP
SeaMonkey
Flock
Mozilla
LeechFTP
Odin Secure FTP Expert
WinFTP
FTP Surfer
FTPGetter
ALFTP
Internet Explorer
Dreamweaver
DeluxeFTP
Google Chrome
Chromium / SRWare Iron
ChromePlus
Bromium (Yandex Chrome)
Nichrome
Comodo Dragon
RockMelt
K-Meleon
Epic
Staff-FTP
AceFTP
Global Downloader
FreshFTP
BlazeFTP
NETFile
GoFTP
3D-FTP
Easy FTP
Xftp
FTP Now
Robo-FTP
LinasFTP
Cyberduck
Putty
Notepad + +
CoffeeCup Visual Site Designer
FTPShell
FTPInfo
NexusFile
FastStone Browser
CoolNovo
WinZip
Yandex.Internet
MyFTP
sherrod FTP
NovaFTP
Windows Mail
Windows Live Mail
Becky!
Pocomail
IncrediMail
The Bat!
Outlook
Thunderbird
FastTrack
Download: Pony 1.9.rar (panel + builder + stub source)
[HIDE-THANKS]
This link is hidden for visitors. Please Log in or register now.
Mirror:
This link is hidden for visitors. Please Log in or register now.
Credits: Unic0de
server.exe
RESULTS: 16/35
AVG Free - Virus found Win32/Heur
ArcaVir -
Avast 5 - Win32:Agent-AOOD [Trj]
AntiVir (Avira) - TR/Crypt.XPACK.Gen3
BitDefender - Gen:Variant.Kazy.61489
VirusBuster -
Clam -
COMODO -
Dr.Web - Trojan.PWS.Stealer.1724
eTrust-Vet -
F-PROT -
F-Secure - Gen:Variant.Kazy.61489
G Data - Gen:Variant.Kazy.61489, Win32:Agent-AOOD [Trj]
IKARUS - Trojan-PWS.Win32.Fareit
Kaspersky - HEUR:Trojan.Win32.Generic
McAfee -
MS Essentials -
ESET NOD32 - Trojan.Win32/PSW.Fareit.A
Norman -
Norton - Downloader.Ponik
Panda - Malware
A-Squared - Trojan-PWS.Win32.Fareit!IK
Quick Heal -
Solo -
Sophos -
Trend Micro - BKDR_PONY.SM
VBA32 -
Vexira -
Zoner AntiVirus -
Ad-Aware -
BullGuard - Gen:Variant.Kazy.61489
Immunet - Gen:Variant.Kazy.61489
K7 Ultimate -
NANO -
VIPRE -
File Name Pony.exe
File Size: 34816
File MD5: 0ca0aa324446ffada395d644d9bfbe48
File SHA1: 3c8ea0ccbb10390c164bc2ab00370e145a3d53be
Check Time: 2012-12-23 13:38:30
Scan report generated by
This link is hidden for visitors. Please Log in or register now.
Last edited by a moderator: