MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22deb6c18e0ee7d02838c539bbe5c76d877137fa1fc459ec208ad133a671cf65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments 1

SHA256 hash: 22deb6c18e0ee7d02838c539bbe5c76d877137fa1fc459ec208ad133a671cf65
SHA3-384 hash: cf4278c19d7b44c4df33c95f5fb365773df67f0a45e9390adb5546c686e0ea778e8bbcd30590cdde546306b5b6311060
SHA1 hash: 253f1322e11f6b571ac961cdb5efe696821a5c5e
MD5 hash: a743f0263ff0ecc3c789d61beb4ee0a6
humanhash: eighteen-blue-golf-double
File name:a743f0263ff0ecc3c789d61beb4ee0a6
Download: download sample
Signature PureLogsStealer
File size:5'569'143 bytes
First seen:2024-02-03 20:13:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:ngOu4J53nOeLQiKfz7TniRdxgZajUy4qPA8Xfir7fv+ild1Qml:gOu63Oe0jP6/gZaTnP3a7fv1GU
TLSH T19A4633C121244C8ED91E9737AF8A6A574CFE0857CA05233DA479DA90235CA7E2B37FC5
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter zbetcheckin
Tags:PureLogStealer zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
FR FR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:npp86Installerx64.exe
File size:5'613'056 bytes
SHA256 hash: 0e799bc7f1651cf27079ad83feeb0d26419f64e58601c85b6f55ffa15ef9ab8b
MD5 hash: d8b897481e51cfab29862e8f9d5a039d
MIME type:application/x-dosexec
Signature PureLogsStealer
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
advpack anti-vm CAB explorer installer lolbin packed rundll32 setupapi sfx shell32 tiny
Threat name:
ByteCode-MSIL.Trojan.Seraph
Status:
Malicious
First seen:
2024-01-29 23:01:25 UTC
File Type:
Binary (Archive)
Extracted files:
59
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_Redline_Stealer
Author:Varp0s

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PureLogsStealer

zip 22deb6c18e0ee7d02838c539bbe5c76d877137fa1fc459ec208ad133a671cf65

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2024-02-03 20:13:18 UTC

url : hxxp://194.4.49.187/fire/npp86Installerx64.zip