MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a847b574c6b43c4e5b517bc1487fca6bf83e0f4b3d7517ee32506289a099ee42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: a847b574c6b43c4e5b517bc1487fca6bf83e0f4b3d7517ee32506289a099ee42
SHA3-384 hash: 92be3ea3849e39b7c712ff20041c457338c346fdfe50bad6c13df293d545523b2790f37f92d10bbb53b5ee923e60bf6f
SHA1 hash: e1b528f4437613cde1cf9dddd5414de76a28f8fa
MD5 hash: ed38e3d4ba9a727b436994c2de44b49a
humanhash: cup-chicken-diet-burger
File name:6b58b6.msi
Download: download sample
Signature PureLogsStealer
File size:6'701'056 bytes
First seen:2024-09-21 20:04:10 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 196608:FBstEAABrjAQq8v8R9hZugbD2RDUrn0P:FKVA9vSPRiUz
TLSH T14E66335137C94A35D2A6063688B283653E377CB50BF085CF1DB1F91C9E34AC2AD793A2
TrID 80.0% (.MSI) Microsoft Windows Installer (454500/1/170)
10.7% (.MST) Windows SDK Setup Transform script (61000/1/5)
7.8% (.MSP) Windows Installer Patch (44509/10/5)
1.4% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter smica83
Tags:HUN msi PureLogStealer signed

Code Signing Certificate

Organisation:Kofax, Inc.
Issuer:DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Algorithm:sha256WithRSAEncryption
Valid from:2022-07-20T00:00:00Z
Valid to:2025-07-16T23:59:59Z
Serial number: 0c52c077f9efb86710bec82aba633aaa
Thumbprint Algorithm:SHA256
Thumbprint: 8cddc280cdc593b4c85aa18b807559375557ce8d6355b10e33fd557a6bd5ec88
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
Execution Generic Network
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
crypto expand fingerprint installer keylogger lolbin packed shell32 wix
Result
Threat name:
PureLog Stealer
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Creates files in the system32 config directory
Disables security and backup related services
Found direct / indirect Syscall (likely to bypass EDR)
Found evasive API chain (may stop execution after checking mutex)
Installs new ROOT certificates
Modifies the windows firewall
Reads the Security eventlog
Reads the System eventlog
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Generic Downloader
Yara detected PureLog Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1515170 Sample: 6b58b6.msi Startdate: 21/09/2024 Architecture: WINDOWS Score: 100 140 Yara detected PureLog Stealer 2->140 142 Sigma detected: Invoke-Obfuscation CLIP+ Launcher 2->142 144 Yara detected Generic Downloader 2->144 146 2 other signatures 2->146 12 msiexec.exe 88 28 2->12         started        15 PrintixService.exe 2->15         started        19 VSSVC.exe 28 2->19         started        21 6 other processes 2->21 process3 dnsIp4 106 C:\Windows\Installer\MSI7E85.tmp, PE32 12->106 dropped 108 C:\Windows\Installer\MSI55C2.tmp, PE32 12->108 dropped 110 C:\Windows\Installer\MSI2AFE.tmp, PE32 12->110 dropped 112 C:\Windows\Installer\MSI29E3.tmp, PE32 12->112 dropped 23 msiexec.exe 1 2 12->23         started        25 msiexec.exe 3 12->25         started        124 assets.printix.net 18.245.46.51, 443, 49168, 49192 AMAZON-02US United States 15->124 132 Installs new ROOT certificates 15->132 134 Reads the Security eventlog 15->134 136 Reads the System eventlog 15->136 27 cmd.exe 15->27         started        138 Found direct / indirect Syscall (likely to bypass EDR) 19->138 file5 signatures6 process7 process8 29 PrintixClientWindows.exe 2 23->29         started        32 expand.exe 4 23->32         started        34 icacls.exe 23->34         started        36 icacls.exe 23->36         started        38 cmd.exe 25->38         started        40 schtasks.exe 27->40         started        file9 114 C:\Users\user\...\PrintixClientWindows.tmp, PE32 29->114 dropped 42 PrintixClientWindows.tmp 30 28 29->42         started        116 C:\Users\...\PrintixClientWindows.exe (copy), PE32 32->116 dropped 118 C:\...\2710beaee17f294d97dbca345fe0eeb2.tmp, PE32 32->118 dropped process10 file11 98 C:\Program Files\printix.net\...\is-TFILH.tmp, PE32 42->98 dropped 100 C:\Program Files\printix.net\...\is-N9E94.tmp, PE32 42->100 dropped 102 C:\Program Files\printix.net\...\is-KNPRQ.tmp, PE32 42->102 dropped 104 8 other files (1 malicious) 42->104 dropped 148 Disables security and backup related services 42->148 46 cmd.exe 42->46         started        49 Dism.exe 42->49         started        52 Dism.exe 42->52         started        54 10 other processes 42->54 signatures12 process13 file14 150 Uses schtasks.exe or at.exe to add and modify task schedules 46->150 152 Uses netsh to modify the Windows network and firewall settings 46->152 154 Modifies the windows firewall 46->154 56 netsh.exe 16 46->56         started        58 netsh.exe 46->58         started        60 netsh.exe 46->60         started        72 18 other processes 46->72 82 C:\Users\user\AppData\Local\...\DismHost.exe, PE32+ 49->82 dropped 84 C:\Users\user\AppData\Local\...\wdscore.dll, PE32+ 49->84 dropped 86 C:\Users\user\AppData\...\WimProvider.dll.mui, PE32+ 49->86 dropped 94 28 other files (none is malicious) 49->94 dropped 62 DismHost.exe 49->62         started        88 C:\Users\user\AppData\Local\...\wdscore.dll, PE32+ 52->88 dropped 90 C:\Users\user\AppData\...\WimProvider.dll.mui, PE32+ 52->90 dropped 92 C:\Users\user\...\UnattendProvider.dll.mui, PE32+ 52->92 dropped 96 28 other files (none is malicious) 52->96 dropped 65 DismHost.exe 52->65         started        156 Creates files in the system32 config directory 54->156 67 PrintixClient.exe 54->67         started        70 net1.exe 54->70         started        74 5 other processes 54->74 signatures15 process16 dnsIp17 158 Found evasive API chain (may stop execution after checking mutex) 62->158 120 127.0.0.1 unknown unknown 67->120 76 chrome.exe 67->76         started        signatures18 process19 dnsIp20 122 239.255.255.250 unknown Reserved 76->122 79 chrome.exe 76->79         started        process21 dnsIp22 126 auth2.printix.net 20.103.202.45, 443, 49193, 49198 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 79->126 128 sign-in.printix.net 172.201.71.85, 443, 49172, 49173 IFX18747US United States 79->128 130 12 other IPs or domains 79->130
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery evasion persistence privilege_escalation
Behaviour
Checks SCSI registry key(s)
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy service COM API
Browser Information Discovery
Enumerates physical storage devices
Event Triggered Execution: Installer Packages
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
Checks installed software on the system
Drops file in Program Files directory
Drops file in Windows directory
Executes dropped EXE
Launches sc.exe
Loads dropped DLL
Drops file in System32 directory
Adds Run key to start application
Blocklisted process makes network request
Enumerates connected drives
Modifies Windows Firewall
Modifies file permissions
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_APT29_WINELOADER_Backdoor
Author:daniyyell
Description:Detects APT29's WINELOADER backdoor variant used in phishing campaigns, this rule also detect bad pdf,shtml,htm and vbs or maybe more depends
Reference:https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments