MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5cefdb8a9e0120db5da9f51859e4a064efd35ae86080f63bf05c2170cce284b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
PureLogsStealer
Vendor detections: 8
| SHA256 hash: | 5cefdb8a9e0120db5da9f51859e4a064efd35ae86080f63bf05c2170cce284b2 |
|---|---|
| SHA3-384 hash: | 35f9ae92d287d1e0443143c00ec8440bf8553efdc8410a360eb535c9319b4f9337f54499a963a2a58f2415352ca9fde4 |
| SHA1 hash: | 731740b19cb72212933c652350ef20f8b6ceee63 |
| MD5 hash: | 1b6cd788bab80e69b24a582f747de0a4 |
| humanhash: | massachusetts-hydrogen-oklahoma-uncle |
| File name: | Purchase_Order_July_-CDF9837E7488349383930038743_docx.js |
| Download: | download sample |
| Signature | PureLogsStealer |
| File size: | 1'024'869 bytes |
| First seen: | 2026-08-18 19:07:51 UTC |
| Last seen: | 2026-08-18 19:08:56 UTC |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 3072:+MdmhT9BbsqRsVRbGdyQ4HJ6QVWaZRPjg29/M0MRpPZV8XZNyu0k+07mUOUQeVTa:SEPj/MRtBgkscnR6cBZHso3YjtLd5i |
| TLSH | T1CA25F9CF6376091C648A7A4FC4386E9E7A9ACF830510FCBABDA45947C50C70253B5B6B |
| Magika | javascript |
| Reporter | |
| Tags: | js PureLogsStealer |
Intelligence
File Origin
# of uploads :
2
# of downloads :
147
Origin country :
CHVendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
cmd conhost downloader lolbin masquerade powershell repaired
Score:
89%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Detection:
purelogs
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-05 02:13:40 UTC
File Type:
Text (JavaScript)
AV detection:
11 of 23 (47.83%)
Threat level:
2/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
PureCrypter
Result
Malware family:
n/a
Score:
8/10
Tags:
collection discovery execution persistence
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Time Discovery
Accesses Microsoft Outlook profiles
Checks computer location settings
Registers new Windows logon scripts automatically executed at logon.
Badlisted process makes network request
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.