🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcc0c41fa3484b44e18dd239095bb69fcccc0a6bea17dd186ab64d95283480c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: dcc0c41fa3484b44e18dd239095bb69fcccc0a6bea17dd186ab64d95283480c7
SHA3-384 hash: 9e9492845526ea6d316fdef5ba7e491fe8c02497d25b5a0fa4058cf9ea2d5ae563b3f427941b7cd5a842a6c1eb7ca615
SHA1 hash: c0f73c6cece39a455542483861f44b356dfbb601
MD5 hash: bdb0053f2696fe38c78254e13684ebca
humanhash: cat-yankee-happy-hotel
File name:dcc0c41fa3484b44e18dd239095bb69fcccc0a6bea17dd186ab64d95283480c7
Download: download sample
Signature PureLogsStealer
File size:1'064'960 bytes
First seen:2026-02-05 15:41:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'246 x AgentTesla, 20'509 x Formbook, 12'377 x SnakeKeylogger)
ssdeep 12288:chAEovbiqYX7cERJccHS42xEVR6N41aIRnCKk7U1QIp4HPws9Ml/I2uG9/j0Mtu0:c3aMIERSx7N43Nk7U1QA4HPqeG90Mf
TLSH T1E635015027ABCF03D0465AB119A3E3B50E78CE996854D7878EF5AEBF3D3A58538442F0
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10522/11/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon 72ceaeaeb2968eaa (57 x AgentTesla, 11 x Formbook, 7 x RemcosRAT)
Reporter adrian__luca
Tags:exe PureLogsStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dcc0c41fa3484b44e18dd239095bb69fcccc0a6bea17dd186ab64d95283480c7
Verdict:
Malicious activity
Analysis date:
2026-02-05 20:42:59 UTC
Tags:
stealer purecrypter purehvnc netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
virus shell msil
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-01-26T15:33:00Z UTC
Last seen:
2026-02-06T10:12:00Z UTC
Hits:
~100
Gathering data
Threat name:
ByteCode-MSIL.Trojan.PureLogs
Status:
Malicious
First seen:
2026-01-26 18:31:50 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
c6d2c7ba95ef957071441ed5a7ea342035bf7276fc5109beea74e615a501b28e
MD5 hash:
1a2c1ff996187ce367bf0cca60952de9
SHA1 hash:
4501bd3a6877b6c8168d5fdd8b5aca395b71b210
SH256 hash:
d74a703718528bb31da0daaafbf2338c3d080d9bee469c45e88cb1011fd940f2
MD5 hash:
677196c6ae7508f8e245d7d505f5f92e
SHA1 hash:
46524bc9f201a9cd246249d0e890c8e308935fd2
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
192b9b2f287dee6670562c8a04d0a89ce8c9edeca69e7a48461737f79d1d9111
MD5 hash:
ea3b18b687e2ac3f7a1a6c8cdcd4725d
SHA1 hash:
a17a8f8d0a28e2f94eeba6f7707964624d944bb8
SH256 hash:
1d4ff1c4d038c314a85613cb8f9c331bbd1a8b2ee74d99cbbe4bd0fd1e0e6172
MD5 hash:
352f387c7a2de8875dfae1c93bffc9a8
SHA1 hash:
6c45d60897daf14ed1f78284f6a757ca776639b9
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
dcc0c41fa3484b44e18dd239095bb69fcccc0a6bea17dd186ab64d95283480c7
MD5 hash:
bdb0053f2696fe38c78254e13684ebca
SHA1 hash:
c0f73c6cece39a455542483861f44b356dfbb601
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments