๐ฅ MD5: b2647b263c14226c62fe743dbff5c70a
๐ฅ C2: 147.124.219.201:65535
https://netresec.com/?b=257eead
I analyzed some PureLogs Stealer malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retrieves a .pdf file from a legitimate website. The dropper I will demo here downloaded this fi[...]
PureLogs Forensics
๐ง Dropper connects to legitimate website
๐ A fake PDF is downloaded over HTTPS
๐พ The fake PDF is decrypted to a #PureLogs DLL
โ๏ธ InstallUtil.exe or RegAsm.exe is started.
๐ PureLogs DLL is injected into the running process
๐พ PureLogs connects to C2 server
IOC List
๐ฅ 91.92.120.101:62520
๐ฅ 91.92.120.101:65535
https://netresec.com/?b=257eead
I analyzed some PureLogs Stealer malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retrieves a .pdf file from a legitimate website. The dropper I will demo here downloaded this fi[...]
CapLoader includes a feature for Port Independent Protocol Identification (PIPI), which can detect which protocol is being used inside of TCP and UDP sessions without relying on the port number. In this video CapLoader identifies the PureLogs C2 protocol. The PureLogs protocol detection was added to[...]
Campagne #Malware #Italy Week 19
โ ๏ธ๐ฅ๐ป๐ฃ
#AgentTesla: Documenti
#GuLoader: Ordine
#RemcosRat: Bank
#Formbook: Preventivo
#PureLogs: Ordine
Some fresh #pureloader + #purelogs #stealer
https://app.any.run/tasks/b7141b83-ab60-4072-b208-f6cbdeb224f2
c2: 91.92.253.88
Campagne #Malware #Italy Week 40
๐ฅ Persistenti
#AgentTesla: Ordine d'acquisto
#Ursnif - #PureLogs: #AgenziaEntrate
#SpyNote: #APK Bancario
๐ฃ D'eccezione
#PikaBot: Resend link ZIP