🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36f7787c221587cdccd6280c159da66ca32e83c2a7ce5b1edaf62dbf8aefd08d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 36f7787c221587cdccd6280c159da66ca32e83c2a7ce5b1edaf62dbf8aefd08d
SHA3-384 hash: 64782626ba27a122d3ea273fb6f5ba65e8e50725b1ca0743ed1a1990c17d43ef686741027fd32bc6bd933c4e2d2bfc1d
SHA1 hash: b184bf7dfec9c00f62aaac594d6cb952e93f9fce
MD5 hash: 8704348f2e675106dafa0aaec7e76a86
humanhash: red-london-timing-massachusetts
File name:shipping Doc787863553553.js
Download: download sample
Signature PureLogsStealer
File size:299'090 bytes
First seen:2026-09-04 12:33:01 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:L2FH0Oa2kQkWmCIjoS5VMEHQcdtTT0bXE0w5ahCca3FG:SPTkQkPZZTob0fahi1G
TLSH T148544D76742BAC83C7FB8B5C9A6262C4B440513B25D8335175FCA3C19F67AA89B4CF90
Magika javascript
Reporter abuse_ch
Tags:js PureLogsStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-04T05:41:00Z UTC
Last seen:
2026-09-04T09:31:00Z UTC
Hits:
~100
Result
Threat name:
PureLogs Stealer
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Creates processes via WMI
Drops script or batch files to the startup folder
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Javascript file is likely language aware (will only work on specific systems)
JavaScript source code contains functionality to generate code involving a shell, file or stream
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Obfuscated command line found
Sigma detected: Drops script at startup location
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected MSIL Injector
Yara detected Powershell download and execute
Yara detected PureLogs Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1968580 Sample: shipping Doc787863553553.js Startdate: 04/09/2026 Architecture: WINDOWS Score: 100 59 resc.cloudinary.com.cdn.cloudflare.net 2->59 61 res.cloudinary.com 2->61 63 8 other IPs or domains 2->63 89 Suricata IDS alerts for network traffic 2->89 91 Antivirus detection for URL or domain 2->91 93 Multi AV Scanner detection for submitted file 2->93 95 13 other signatures 2->95 10 powershell.exe 14 15 2->10         started        14 wscript.exe 1 2->14         started        16 wscript.exe 1 3 2->16         started        19 2 other processes 2->19 signatures3 process4 dnsIp5 75 cloudinary.map.fastly.net 151.101.129.137, 443, 49707 FASTLY-FastlyIncUS Canada 10->75 77 lively-fog-af49.pablosoftwareplus.workers.dev 172.67.128.144, 443, 49702, 49719 CLOUDFLARENET-CloudflareIncUS Canada 10->77 119 Found many strings related to Crypto-Wallets (likely being stolen) 10->119 121 Writes to foreign memory regions 10->121 123 Modifies the context of a thread in another process (thread injection) 10->123 125 Injects a PE file into a foreign processes 10->125 21 MSBuild.exe 14 6 10->21         started        25 conhost.exe 10->25         started        27 powershell.exe 14->27         started        55 shipping Doc787863....js:Zone.Identifier, ASCII 16->55 dropped 57 C:\Users\user\...\shipping Doc787863553553.js, ASCII 16->57 dropped 127 Wscript starts Powershell (via cmd or directly) 16->127 129 Obfuscated command line found 16->129 131 Drops script or batch files to the startup folder 16->131 133 3 other signatures 16->133 79 127.0.0.1 unknown unknown 19->79 29 conhost.exe 19->29         started        file6 signatures7 process8 dnsIp9 71 64.89.160.45, 49714, 49720, 49721 GHOSTYNETWORKSUS Luxembourg 21->71 97 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 21->97 99 Tries to steal Mail credentials (via file / registry access) 21->99 101 Found many strings related to Crypto-Wallets (likely being stolen) 21->101 109 3 other signatures 21->109 31 chrome.exe 1 21->31         started        34 chrome.exe 21->34 injected 36 chrome.exe 21->36 injected 73 resc.cloudinary.com.cdn.cloudflare.net 104.16.78.6, 443, 49722 CLOUDFLARENET-CloudflareIncUS Canada 27->73 103 Writes to foreign memory regions 27->103 105 Modifies the context of a thread in another process (thread injection) 27->105 107 Injects a PE file into a foreign processes 27->107 38 MSBuild.exe 27->38         started        41 conhost.exe 27->41         started        signatures10 process11 dnsIp12 87 192.168.2.10, 138, 443, 49701 unknown unknown 31->87 43 chrome.exe 31->43         started        111 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 38->111 113 Tries to steal Mail credentials (via file / registry access) 38->113 115 Tries to harvest and steal browser information (history, passwords, etc) 38->115 117 4 other signatures 38->117 46 chrome.exe 38->46         started        48 chrome.exe 38->48 injected 50 chrome.exe 38->50 injected signatures13 process14 dnsIp15 81 www.google.com 142.251.155.119, 443, 49725, 49726 GOOGLE-GoogleLLCUS United States 43->81 83 googlehosted.l.googleusercontent.com 142.251.35.97, 443, 49741, 49742 GOOGLE-GoogleLLCUS United States 43->83 85 clients2.googleusercontent.com 43->85 52 chrome.exe 46->52         started        process16 dnsIp17 65 142.250.176.65, 443, 49771, 49772 GOOGLE-GoogleLLCUS United States 52->65 67 mobile-gtalk.l.google.com 142.251.107.188, 49777, 5228 GOOGLE-GoogleLLCUS United States 52->67 69 5 other IPs or domains 52->69
Gathering data
Threat name:
Script-JS.Trojan.ObfDownloader
Status:
Malicious
First seen:
2026-09-04 12:34:22 UTC
File Type:
Text (JavaScript)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
collection discovery execution persistence privilege_escalation
Behaviour
outlook_win_path
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Command and Scripting Interpreter: PowerShell
Creates a file in the Startup directory
Badlisted process makes network request
Process spawned unexpected child process
Malware Config
Dropper Extraction:
https://lively-fog-af49.pablosoftwareplus.workers.dev/Lijvd
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments