🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 38d037df5a3fc9efa34e0a67a5e40eaf2456348dccc9e7e00e0ed0375db3056a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 38d037df5a3fc9efa34e0a67a5e40eaf2456348dccc9e7e00e0ed0375db3056a
SHA3-384 hash: eb3f3c13ee22f58ef1c4a1a435d76fe6f20722d7c0d2b090d24b2b14912f57f54edb37b3f44babe0aec1fd3640aab600
SHA1 hash: 6f37e84b01260d96645070f0dc7fee638168298c
MD5 hash: 13e899a11c44561995c0b44bb69967dc
humanhash: fifteen-hydrogen-sixteen-iowa
File name:New offer quotes.js
Download: download sample
Signature PureLogsStealer
File size:1'499'727 bytes
First seen:2026-09-17 13:01:55 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:e48CMqPzvJyeCUWLqv3bACqxjUoy7sCHIk259aEDUqglfABD9ycx:e6VVyYW2TACpBIk2faeXx
TLSH T1E665017E79D965715AFED39CBBDBED4D27F1A4C2B21CDA84800A5E0C652E683C4C3806
Magika batch
Reporter abuse_ch
Tags:js PureLogsStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
attrib base64 obfuscated powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-17T09:47:00Z UTC
Last seen:
2026-09-18T10:51:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
100 / 100
Signature
Creates a thread in another existing process (thread injection)
Creates an autostart registry key pointing to binary in C:\Windows
Creates processes via WMI
Early bird code injection technique detected
Found suspicious powershell code related to unpacking or dynamic code loading
Hijacks the control flow in another process
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sigma detected: Invoke-Obfuscation Via Stdin
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potential WinAPI Calls Via CommandLine
Sigma detected: Powershell launch wmic via class
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses attrib.exe to hide files
Uses cmd line tools excessively to alter registry or file data
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1974232 Sample: New offer quotes.js Startdate: 17/09/2026 Architecture: WINDOWS Score: 100 146 Sigma detected: Powershell launch wmic via class 2->146 148 Malicious sample detected (through community Yara rule) 2->148 150 Multi AV Scanner detection for submitted file 2->150 152 5 other signatures 2->152 13 wscript.exe 1 1 2->13         started        16 conhost.exe 2->16         started        18 conhost.exe 2->18         started        20 2 other processes 2->20 process3 signatures4 180 JScript performs obfuscated calls to suspicious functions 13->180 182 Wscript starts Powershell (via cmd or directly) 13->182 184 Windows Scripting host queries suspicious COM object (likely to drop second stage) 13->184 186 2 other signatures 13->186 22 cmd.exe 1 13->22         started        25 powershell.exe 8 13->25         started        28 cmd.exe 16->28         started        30 cmd.exe 18->30         started        32 conhost.exe 20->32         started        process5 file6 166 Uses attrib.exe to hide files 22->166 34 powershell.exe 22->34         started        36 cmd.exe 1 22->36         started        38 cmd.exe 1 22->38         started        46 7 other processes 22->46 134 C:\Users\user\AppData\...\196410053352063.cmd, DOS 25->134 dropped 168 Found suspicious powershell code related to unpacking or dynamic code loading 25->168 170 Creates processes via WMI 25->170 40 conhost.exe 25->40         started        172 Suspicious powershell command line found 28->172 174 Wscript starts Powershell (via cmd or directly) 28->174 176 Uses cmd line tools excessively to alter registry or file data 28->176 42 powershell.exe 28->42         started        48 2 other processes 28->48 44 powershell.exe 30->44         started        50 2 other processes 30->50 signatures7 process8 process9 52 powershell.exe 1 46 34->52         started        56 findstr.exe 1 36->56         started        58 findstr.exe 1 38->58         started        60 cmd.exe 42->60         started        62 cmd.exe 44->62         started        64 findstr.exe 1 46->64         started        66 findstr.exe 1 46->66         started        68 findstr.exe 1 46->68         started        70 findstr.exe 1 46->70         started        file10 128 C:\Users\user\...\nls_cache_OEHFLQKZh.cmd, DOS 52->128 dropped 130 C:\Users\user\...\nls_cache_GXZNLUHW.cmd, DOS 52->130 dropped 132 C:\Users\user\AppData\Local\...\nls_cache.cfg, DOS 52->132 dropped 154 Hijacks the control flow in another process 52->154 156 Creates an autostart registry key pointing to binary in C:\Windows 52->156 158 Writes to foreign memory regions 52->158 164 3 other signatures 52->164 72 choice.exe 52->72         started        76 conhost.exe 52->76         started        160 Wscript starts Powershell (via cmd or directly) 60->160 78 powershell.exe 60->78         started        80 cmd.exe 60->80         started        88 7 other processes 60->88 162 Early bird code injection technique detected 62->162 82 cmd.exe 62->82         started        84 cmd.exe 62->84         started        86 cmd.exe 62->86         started        90 6 other processes 62->90 signatures11 process12 dnsIp13 138 2.27.62.208, 4449, 49745, 49746 VPSLAB-NETWORKSID Germany 72->138 178 Unusual module load detection (module proxying) 72->178 92 conhost.exe 72->92         started        94 powershell.exe 78->94         started        97 findstr.exe 80->97         started        99 findstr.exe 82->99         started        101 findstr.exe 84->101         started        103 findstr.exe 86->103         started        107 5 other processes 88->107 105 findstr.exe 90->105         started        109 2 other processes 90->109 signatures14 process15 signatures16 188 Hijacks the control flow in another process 94->188 190 Writes to foreign memory regions 94->190 192 Maps a DLL or memory area into another process 94->192 111 choice.exe 94->111         started        114 conhost.exe 94->114         started        process17 signatures18 194 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 111->194 196 Tries to steal Mail credentials (via file / registry access) 111->196 198 Tries to harvest and steal browser information (history, passwords, etc) 111->198 200 4 other signatures 111->200 116 chrome.exe 111->116         started        119 conhost.exe 111->119         started        121 chrome.exe 111->121 injected 123 2 other processes 111->123 process19 dnsIp20 136 192.168.2.5, 138, 443, 4449 unknown unknown 116->136 125 chrome.exe 116->125         started        process21 dnsIp22 140 mobile-gtalk.l.google.com 142.250.141.188, 49773, 5228 GOOGLE-GoogleLLCUS United States 125->140 142 www.google.com 142.251.156.119, 443, 49753, 49755 GOOGLE-GoogleLLCUS United States 125->142 144 5 other IPs or domains 125->144
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
collection defense_evasion discovery execution persistence privilege_escalation
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Views/modifies file attributes
outlook_office_path
outlook_win_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
Executes a command shell one-liner
System Time Discovery
Hide Artifacts: Hidden Files and Directories
Accesses Microsoft Outlook profiles
Adds Run key to start application
Checks computer location settings
Creates a file in the Startup directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments