MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd490f5e80460d13b9424541da5fbd3aaf0a2c458e98bedeea03c6d99d036780. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureLogsStealer


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: dd490f5e80460d13b9424541da5fbd3aaf0a2c458e98bedeea03c6d99d036780
SHA3-384 hash: 6dddd938225a1a3d18bc7e9772ffd15aaa0cec547b513ead44e36032e10cb6826359700c9a1524ecdf929021c8198a97
SHA1 hash: f04fb602220995b2cd58842f65861e752ecbd06f
MD5 hash: bf33a9d8c54d1a3532388dfe43d1add6
humanhash: butter-yellow-robert-mobile
File name:DOC BL, CI& PL.vbs
Download: download sample
Signature PureLogsStealer
File size:2'910'977 bytes
First seen:2026-08-06 05:39:09 UTC
Last seen:2026-08-06 12:14:24 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24576:pQT2M8zY45BmWOE5o3L04xzG26OK3JWhAX6gA7c4pJ6hjVLG876O2Wk3WMP3X+Un:Y
TLSH T1CCD5939EF125BA451FBAA30FEB80D4A90575BD168BDBF78B6C6DA1D30203A306CF1415
Magika vba
Reporter abuse_ch
Tags:PureLogsStealer vbs

Intelligence


File Origin
# of uploads :
2
# of downloads :
96
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted evasive obfuscated
Verdict:
Malicious
File Type:
text
First seen:
2026-08-06T01:23:00Z UTC
Last seen:
2026-08-08T03:39:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates a thread in another existing process (thread injection)
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Unusual module load detection (module proxying)
Uses attrib.exe to hide files
Uses whoami command line tool to query computer and username
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected MSIL Injector
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1953088 Sample: DOC BL, CI& PL.vbs Startdate: 06/08/2026 Architecture: WINDOWS Score: 100 85 Malicious sample detected (through community Yara rule) 2->85 87 Yara detected MSIL Injector 2->87 89 Yara detected UAC Bypass using CMSTP 2->89 91 4 other signatures 2->91 9 cmd.exe 1 2->9         started        12 wscript.exe 2 2->12         started        15 cmd.exe 3 2->15         started        process3 file4 103 Suspicious powershell command line found 9->103 105 Wscript starts Powershell (via cmd or directly) 9->105 107 Uses attrib.exe to hide files 9->107 17 powershell.exe 12 9->17         started        19 conhost.exe 9->19         started        71 C:\Users\user\AppData\Local\...\005FB859.cmd, DOS 12->71 dropped 109 VBScript performs obfuscated calls to suspicious functions 12->109 111 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->111 113 Suspicious execution chain found 12->113 115 WScript reads language and country specific registry keys (likely country aware script) 12->115 21 cmd.exe 1 12->21         started        24 powershell.exe 15->24         started        26 conhost.exe 15->26         started        28 attrib.exe 15->28         started        signatures5 process6 signatures7 30 cmd.exe 3 17->30         started        93 Suspicious powershell command line found 21->93 95 Wscript starts Powershell (via cmd or directly) 21->95 34 powershell.exe 12 21->34         started        36 conhost.exe 21->36         started        97 Writes to foreign memory regions 24->97 99 Creates a thread in another existing process (thread injection) 24->99 101 Injects a PE file into a foreign processes 24->101 38 prevhost.exe 24->38         started        process8 dnsIp9 73 C:\Users\user\AppData\...\prefetch_meta.cfg, DOS 30->73 dropped 143 Suspicious powershell command line found 30->143 145 Wscript starts Powershell (via cmd or directly) 30->145 41 powershell.exe 42 30->41         started        44 conhost.exe 30->44         started        46 powershell.exe 30->46         started        48 attrib.exe 1 30->48         started        50 cmd.exe 1 34->50         started        83 2.27.62.123, 4449, 49720, 49721 VPSLAB-NETWORKSID Germany 38->83 147 Writes to foreign memory regions 38->147 149 Allocates memory in foreign processes 38->149 151 Creates a thread in another existing process (thread injection) 38->151 153 Injects a PE file into a foreign processes 38->153 52 chrome.exe 38->52         started        55 chrome.exe 38->55 injected 57 chrome.exe 38->57 injected file10 signatures11 process12 dnsIp13 117 Writes to foreign memory regions 41->117 119 Uses whoami command line tool to query computer and username 41->119 121 Creates a thread in another existing process (thread injection) 41->121 127 2 other signatures 41->127 59 prevhost.exe 41->59         started        62 whoami.exe 1 41->62         started        123 Suspicious powershell command line found 50->123 125 Wscript starts Powershell (via cmd or directly) 50->125 64 powershell.exe 15 50->64         started        66 conhost.exe 50->66         started        75 192.168.2.6, 138, 443, 4449 unknown unknown 52->75 68 chrome.exe 52->68         started        signatures14 process15 dnsIp16 129 Unusual module load detection (module proxying) 59->129 131 Switches to a custom stack to bypass stack traces 59->131 133 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 59->133 135 Found evasive API chain (may stop execution after checking mutex) 64->135 137 Found stalling execution ending in API Sleep call 64->137 139 Found API chain indicative of debugger detection 64->139 141 2 other signatures 64->141 77 www.google.com 142.251.153.119, 443, 49726, 49728 GOOGLE-GoogleLLCUS United States 68->77 79 mobile-gtalk.l.google.com 142.251.163.188, 49749, 5228 GOOGLE-GoogleLLCUS United States 68->79 81 5 other IPs or domains 68->81 signatures17
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated Obfuscated Scripting.FileSystemObject T1027 T1059.005 VBScript WScript.Shell
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-08-06 05:47:18 UTC
File Type:
Text (VBS)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection defense_evasion discovery execution persistence privilege_escalation
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Views/modifies file attributes
outlook_office_path
outlook_win_path
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Time Discovery
Executes a VBScript file via the Windows Script Host.
Accesses Microsoft Outlook profiles
Checks computer location settings
Creates a file in the Startup directory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments