MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a83a0ea185e95684a202963b7f4acb40e4e148d670ef149aff96853dc46e16c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 12


Intelligence 12 IOCs YARA 4 File information Comments

SHA256 hash: a83a0ea185e95684a202963b7f4acb40e4e148d670ef149aff96853dc46e16c1
SHA3-384 hash: 07ef1bd16f4b7c63dd33c6478533c59881a02884240ec384a985c069360a11e3ddb8d63b0bae29d18b59da0f38122224
SHA1 hash: 41ad155598fd9acb0d8c4b72ce9056b48ef9c3de
MD5 hash: 58082a5543e9a04a66a49097c4da851b
humanhash: march-princess-mike-paris
File name:EDO-SJD2616SHO105.pdf.exe
Download: download sample
Signature PureLogsStealer
File size:1'674'240 bytes
First seen:2026-08-12 07:33:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'192 x AgentTesla, 20'342 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 49152:ADeIVGK1N58ed04Zk6U5PZ4cuLXbl5HmLyAtlQVU92V:aeIVhyy6Z4LLZxmWYlQVUm
TLSH T1CA7523642315DE01C9624BF49D31EBB81BF56E90AA21D3178DFA7DE7B83A7086C052C7
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter abuse_ch
Tags:exe PureLogsStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
SE SE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-12T04:20:00Z UTC
Last seen:
2026-08-13T05:57:00Z UTC
Hits:
~100
Result
Threat name:
PureLogs Stealer
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates a thread in another existing process (thread injection)
Found many strings related to Crypto-Wallets (likely being stolen)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Double Extension File Execution
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses an obfuscated file name to hide its real file extension (double extension)
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected MSIL Injector
Yara detected PureLogs Stealer
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1956613 Sample: EDO-SJD2616SHO105.pdf.exe Startdate: 12/08/2026 Architecture: WINDOWS Score: 100 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected PureLogs Stealer 2->61 63 Yara detected MSIL Injector 2->63 65 7 other signatures 2->65 8 EDO-SJD2616SHO105.pdf.exe 2 2->8         started        11 EDO-SJD2616SHO105.pdf.exe 2 2->11         started        process3 signatures4 67 Found many strings related to Crypto-Wallets (likely being stolen) 8->67 69 Injects a PE file into a foreign processes 8->69 71 Switches to a custom stack to bypass stack traces 8->71 73 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 8->73 13 EDO-SJD2616SHO105.pdf.exe 15 5 8->13         started        17 EDO-SJD2616SHO105.pdf.exe 8->17         started        19 EDO-SJD2616SHO105.pdf.exe 3 11->19         started        process5 dnsIp6 57 64.89.160.76, 49703, 49705, 49706 GHOSTYNETWORKSUS Luxembourg 13->57 75 Tries to steal Mail credentials (via file / registry access) 13->75 77 Found many strings related to Crypto-Wallets (likely being stolen) 13->77 79 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 13->79 87 2 other signatures 13->87 21 chrome.exe 3 13->21         started        24 chrome.exe 2 13->24 injected 26 chrome.exe 2 13->26 injected 28 chrome.exe 2 13->28 injected 81 Writes to foreign memory regions 19->81 83 Creates a thread in another existing process (thread injection) 19->83 85 Injects a PE file into a foreign processes 19->85 30 chrome.exe 19->30         started        32 chrome.exe 19->32 injected 34 chrome.exe 19->34 injected 36 4 other processes 19->36 signatures7 process8 dnsIp9 43 192.168.2.12, 138, 443, 49698 unknown unknown 21->43 38 chrome.exe 2 21->38         started        41 chrome.exe 30->41         started        process10 dnsIp11 45 www.google.com 142.251.156.119, 443, 49714, 49715 GOOGLE-GoogleLLCUS United States 38->45 47 142.251.211.97, 443, 49729 GOOGLE-GoogleLLCUS United States 38->47 53 4 other IPs or domains 38->53 49 142.251.157.119, 443, 49751, 49752 GOOGLE-GoogleLLCUS United States 41->49 51 142.251.167.188, 49774, 5228 GOOGLE-GoogleLLCUS United States 41->51 55 4 other IPs or domains 41->55
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.41 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.Yogi
Status:
Malicious
First seen:
2026-08-12 07:34:34 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
collection discovery persistence privilege_escalation spyware stealer
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Creates a file in the Startup directory
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
a83a0ea185e95684a202963b7f4acb40e4e148d670ef149aff96853dc46e16c1
MD5 hash:
58082a5543e9a04a66a49097c4da851b
SHA1 hash:
41ad155598fd9acb0d8c4b72ce9056b48ef9c3de
SH256 hash:
76e498f6c3056812a6aa5dab98d61ce4f38fb688de62766a3d6b233f68a51f0b
MD5 hash:
68a9e112ca72295fa5caac73cc65232a
SHA1 hash:
36d946402d86bf9e2e06c58dca1afe57258e7b11
SH256 hash:
5e832605bae70e085a26be9e9a965c78d1132e785127e5ae4b83d2e3dcdfef26
MD5 hash:
2f7963f6e78288361ca56517cf1988ae
SHA1 hash:
6bcbc58f8312507f6233147ef80292ec870242c2
SH256 hash:
9c29f9cff53eec75df9124566d677b62ac99080a64f9daca5c13a5bac004db70
MD5 hash:
b57907102ffb4e78629560aa5ed1bd3b
SHA1 hash:
d9acdc0925caab9134cbe43425e05f817841f753
SH256 hash:
60683bc24f609d335b472f1dd9a5997cdc920041a2055a977b22daa008146137
MD5 hash:
09364cfb526e937c4e4db2a73d646329
SHA1 hash:
67fd341e0185f14801743d87dbb6f1a1e6fe8cfa
SH256 hash:
b2a66e9864f81c2800a5afef4bfd1faf7c910e5a43ea2eb9dbb15c8ab6ffc633
MD5 hash:
f0a13fb422cdb1f3ce667df897b5045b
SHA1 hash:
9b6566603e3a292482788924a83a1d94a9cd4627
SH256 hash:
241237172c47921a97378f00993d2a98db4977f60a332dfc1cdbb4e6dc20e3c1
MD5 hash:
e0a6414b2acad4535ce6b3ff76aa1709
SHA1 hash:
c62b1eb49cc1b6c8227f1667bcb9d4b1576098a0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments