MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d71bedbee7358b2ef19cff4d8293749caba871a6470983f1f07e3901aeb2398. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 0d71bedbee7358b2ef19cff4d8293749caba871a6470983f1f07e3901aeb2398
SHA3-384 hash: 4877660f3633abb6232e3fc93b73964010b83fc9eeebad511f1edab7af9ac994d1fdf51ea5e28aeab834bba06ba7e644
SHA1 hash: e8647de3d8d683f202fee4ce7988aa748438695a
MD5 hash: 3cf60017c3b4fcfb39149f18fcaf3338
humanhash: jupiter-fanta-hot-carolina
File name:SOA & INVOICES.vbs
Download: download sample
Signature PureLogsStealer
File size:2'895'029 bytes
First seen:2026-08-06 14:28:56 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24576:ejOeMTl6HMiniC/AfGMiQbmhXH702K+50VA1tdQLHTb/nIfgyVd:Q
TLSH T174D5A6EEE024BE500FB6B30FDB80D8650175BE168B97F68B7C2EA1E30553A70ADB1455
Magika vba
Reporter abuse_ch
Tags:PureLogsStealer vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted evasive masquerade obfuscated
Verdict:
Malicious
File Type:
text
First seen:
2026-08-06T10:20:00Z UTC
Last seen:
2026-08-07T12:43:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates a thread in another existing process (thread injection)
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses attrib.exe to hide files
Uses whoami command line tool to query computer and username
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected MSIL Injector
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1953441 Sample: SOA & INVOICES.vbs Startdate: 06/08/2026 Architecture: WINDOWS Score: 100 87 Malicious sample detected (through community Yara rule) 2->87 89 Multi AV Scanner detection for submitted file 2->89 91 Yara detected MSIL Injector 2->91 93 5 other signatures 2->93 9 cmd.exe 1 2->9         started        12 cmd.exe 2->12         started        14 wscript.exe 2 2->14         started        process3 file4 105 Suspicious powershell command line found 9->105 107 Wscript starts Powershell (via cmd or directly) 9->107 109 Uses attrib.exe to hide files 9->109 17 powershell.exe 12 9->17         started        19 conhost.exe 9->19         started        21 powershell.exe 12->21         started        24 conhost.exe 12->24         started        26 attrib.exe 12->26         started        73 C:\Users\user\AppData\Local\...\025780D0.cmd, DOS 14->73 dropped 111 VBScript performs obfuscated calls to suspicious functions 14->111 113 Windows Scripting host queries suspicious COM object (likely to drop second stage) 14->113 115 Suspicious execution chain found 14->115 117 WScript reads language and country specific registry keys (likely country aware script) 14->117 28 cmd.exe 1 14->28         started        signatures5 process6 signatures7 30 cmd.exe 3 17->30         started        95 Writes to foreign memory regions 21->95 97 Creates a thread in another existing process (thread injection) 21->97 99 Injects a PE file into a foreign processes 21->99 34 prevhost.exe 21->34         started        101 Suspicious powershell command line found 28->101 103 Wscript starts Powershell (via cmd or directly) 28->103 37 powershell.exe 12 28->37         started        39 conhost.exe 28->39         started        process8 dnsIp9 75 C:\Users\user\AppData\...\dcom_lease.dat, DOS 30->75 dropped 141 Suspicious powershell command line found 30->141 143 Wscript starts Powershell (via cmd or directly) 30->143 41 powershell.exe 41 30->41         started        44 conhost.exe 30->44         started        46 powershell.exe 30->46         started        48 attrib.exe 1 30->48         started        77 2.27.62.123, 4449, 49720, 49721 VPSLAB-NETWORKSID Germany 34->77 145 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 34->145 147 Tries to steal Mail credentials (via file / registry access) 34->147 149 Tries to harvest and steal browser information (history, passwords, etc) 34->149 151 5 other signatures 34->151 50 chrome.exe 34->50         started        53 chrome.exe 34->53 injected 55 chrome.exe 34->55 injected 57 chrome.exe 34->57 injected 59 cmd.exe 1 37->59         started        file10 signatures11 process12 dnsIp13 119 Writes to foreign memory regions 41->119 121 Uses whoami command line tool to query computer and username 41->121 123 Creates a thread in another existing process (thread injection) 41->123 129 2 other signatures 41->129 61 prevhost.exe 2 41->61         started        64 whoami.exe 1 41->64         started        79 192.168.2.8, 138, 443, 4449 unknown unknown 50->79 66 chrome.exe 50->66         started        125 Suspicious powershell command line found 59->125 127 Wscript starts Powershell (via cmd or directly) 59->127 69 powershell.exe 15 59->69         started        71 conhost.exe 59->71         started        signatures14 process15 dnsIp16 131 Unusual module load detection (module proxying) 61->131 133 Switches to a custom stack to bypass stack traces 61->133 135 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 61->135 81 android.l.google.com 108.177.122.138, 443, 49749 GOOGLE-GoogleLLCUS United States 66->81 83 ogads-pa.clients6.google.com 142.251.15.95, 443, 49744, 49745 GOOGLE-GoogleLLCUS United States 66->83 85 5 other IPs or domains 66->85 137 Found suspicious powershell code related to unpacking or dynamic code loading 69->137 139 Uses whoami command line tool to query computer and username 69->139 signatures17
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated Obfuscated Scripting.FileSystemObject T1027 T1059.005 VBScript WScript.Shell
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-06 14:29:44 UTC
File Type:
Text (VBS)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection defense_evasion discovery execution persistence privilege_escalation
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Views/modifies file attributes
outlook_office_path
outlook_win_path
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Time Discovery
Executes a VBScript file via the Windows Script Host.
Accesses Microsoft Outlook profiles
Checks computer location settings
Creates a file in the Startup directory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments