A Full Analysis of the Pure #malware_removal Family: Unique and Growing Threat
The folks at ANY.RUN have posted an analysis of the PURE of the #crypter and multifunctional #stealer malware. While advertised as educational software, Malware Bazaar's database has too many listings to support this claim. Check out https://bazaar.abuse.ch/browse.php?search=tag%3ApureCrypter
PURE is purchased via a website and telegram bots often involving Bitcoin. PureCrypter's behavior flow is typical of loader or staged loader malware. They also examine PureLogs and PureMiner. All family members exhibit malicious code behaviors.
Kudos to the ANY.RUN folks for presenting a deeply technical analysis in an excellent narrative.