home.social

#purelogs β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #purelogs, aggregated by home.social.

fetched live
  1. @james_inthe_box Thank you for sharing! The #PureLogs C2 server seems to be on 2.27.62.123:4449
    Turns out JoeSandbox has history for that C2 server since at least 2026-04-08.
    joesandbox.com/analysis/search

  2. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  3. πŸ“’πŸš¨πŸŽ£ Fake purchase order emails are spreading fileless #PureLogs malware through malicious RAR archives, targeting Windows users and stealing browser credentials, crypto wallet data, VPN logins, Discord tokens, and more.

    Read: hackread.com/purchase-emails-f

    #Cybersecurity #Malware #Phishing #Windows

  4. UPDATE: Turns out the whole /wp-admin/js/ directory on VΓ€stkupan's website allows directory listing. Among the files in that directory is "New PO 102456688.exe", which drops #PureLogs.
    πŸ”₯ MD5: b2647b263c14226c62fe743dbff5c70a
    πŸ”₯ C2: 147.124.219.201:65535
    netresec.com/?b=257eead

  5. Do #PureLogs Stealer and #PureCrypter use the same C2 protocol, or is there some way to tell the C2 protocols apart?
    C2 servers:
    πŸ”₯ 45.141.233.100:7708
    πŸ”₯ 144.172.91.74:7709
    πŸ”₯ 62.60.235.100:9100
    πŸ”₯ 65.108.24.103:62050
    πŸ”₯ 91.92.120.102:62050
    πŸ”₯ 192.30.240.242:62520

  6. PureLogs Forensics
    πŸ’§ Dropper connects to legitimate website
    πŸ“„ A fake PDF is downloaded over HTTPS
    πŸ’Ύ The fake PDF is decrypted to a #PureLogs DLL
    βš™οΈ InstallUtil.exe or RegAsm.exe is started.
    πŸ’‰ PureLogs DLL is injected into the running process
    πŸ‘Ύ PureLogs connects to C2 server

    IOC List
    πŸ”₯ 91.92.120.101:62520
    πŸ”₯ 91.92.120.101:65535
    netresec.com/?b=257eead