MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ade88bbc33c4da56fca0d72bb7931c63754c503db1ed6d739737b8c51b1f12af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: ade88bbc33c4da56fca0d72bb7931c63754c503db1ed6d739737b8c51b1f12af
SHA3-384 hash: 43567193322410371e2a427dfe8df2cd0abf3fc82a91d2e60a8521c7dd78794c21d5f4aada77014ff0d48901f89b7ffa
SHA1 hash: 820a1f270a9eff8818e49accbac8d9718456d50d
MD5 hash: 04516f5fefcfc0cff04458d758ee6a26
humanhash: arkansas-xray-black-indigo
File name:ade88bbc33c4da56fca0d72bb7931c63754c503db1ed6d739737b8c51b1f12af
Download: download sample
Signature PureLogsStealer
File size:1'628'160 bytes
First seen:2026-08-10 14:56:00 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'191 x AgentTesla, 20'339 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 49152:UA74JHYiBLrTjl2zF52bDVWqfCSMa74WnUnLds5Jm2:UA74HtLPuU4ICSM8UnU02
TLSH T19B75232816238802C9F27DB12EB4F1B067369DA9F139C2D54FD71EABF8AB1183D41765
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 36b1d1d199b9b632 (1 x PhantomStealer, 1 x PureLogsStealer)
Reporter adrian__luca
Tags:exe PureLogsStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Connection attempt
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 entropy packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-28T01:51:00Z UTC
Last seen:
2026-08-11T02:48:00Z UTC
Hits:
~1000
Gathering data
Gathering data
Threat name:
Win32.Trojan.SnakeKeylogger
Status:
Malicious
First seen:
2026-07-28 13:01:49 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Unpacked files
SH256 hash:
ade88bbc33c4da56fca0d72bb7931c63754c503db1ed6d739737b8c51b1f12af
MD5 hash:
04516f5fefcfc0cff04458d758ee6a26
SHA1 hash:
820a1f270a9eff8818e49accbac8d9718456d50d
SH256 hash:
495fe11bf884249f0a124608fac0cc75ed99588404ddb6d23ec33662b23387ff
MD5 hash:
da7db0fe26a8660d2929b71830c93811
SHA1 hash:
1b6d20049c16723c9d4e294129311b47a0c79848
SH256 hash:
2104d6cd8364c4e9042395d212ef82e0fd1f5d326bd66b5f9542c3a2ebac894c
MD5 hash:
7a2e605f489cd205919bae5d369a7d50
SHA1 hash:
2dcadc1477d82b86fe16838a5bcb5d6374989cf8
SH256 hash:
9d8b345736e8717d6d9d3709848e947a7773eced305200b79457e8e0b1f5b242
MD5 hash:
a1f0b455fb330159dfc4e0229f37199a
SHA1 hash:
42e816028dd8cdeac588b52d3aaefb4535d3ffa1
SH256 hash:
8ae6fd53e31db7d5dd8c979715e1ed0a2e209ea30db4d782b0b9039a8dddb7ae
MD5 hash:
3f3cb7ec1b53d330794a30e31cf74e14
SHA1 hash:
0d8cdbc6a2f5fde09745853009c3d9e226e55ae5
SH256 hash:
61bf92477bbe04d2cdce1152d41434017b2b8bf745d32ad23744203a8bbfb0f6
MD5 hash:
20bd163a6437adc625c015fce3460806
SHA1 hash:
2867afb058f75b3b835b2eff7ef5688be8076332
SH256 hash:
306dbfb77db4cf6d6fadfca79e19343e5b3122addc9e0c8008b55e371d0ba798
MD5 hash:
fbf62dd013ea94a8d5a1b47c687d0930
SHA1 hash:
4a8f404c3dafe6672bc7e73448c55b699fbf2336
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments