π₯ MD5: b2647b263c14226c62fe743dbff5c70a
π₯ C2: 147.124.219.201:65535
https://netresec.com/?b=257eead
I analyzed some PureLogs Stealer malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retrieves a .pdf file from a legitimate website. The dropper I will demo here downloaded this fi[...]
PureLogs Forensics
π§ Dropper connects to legitimate website
π A fake PDF is downloaded over HTTPS
πΎ The fake PDF is decrypted to a #PureLogs DLL
βοΈ InstallUtil.exe or RegAsm.exe is started.
π PureLogs DLL is injected into the running process
πΎ PureLogs connects to C2 server
IOC List
π₯ 91.92.120.101:62520
π₯ 91.92.120.101:65535
https://netresec.com/?b=257eead
I analyzed some PureLogs Stealer malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retrieves a .pdf file from a legitimate website. The dropper I will demo here downloaded this fi[...]
CapLoader includes a feature for Port Independent Protocol Identification (PIPI), which can detect which protocol is being used inside of TCP and UDP sessions without relying on the port number. In this video CapLoader identifies the PureLogs C2 protocol. The PureLogs protocol detection was added to[...]
Campagne #Malware #Italy Week 19
β οΈπ₯π»π£
#AgentTesla: Documenti
#GuLoader: Ordine
#RemcosRat: Bank
#Formbook: Preventivo
#PureLogs: Ordine
Some fresh #pureloader + #purelogs #stealer
https://app.any.run/tasks/b7141b83-ab60-4072-b208-f6cbdeb224f2
c2: 91.92.253.88
Campagne #Malware #Italy Week 40
π₯ Persistenti
#AgentTesla: Ordine d'acquisto
#Ursnif - #PureLogs: #AgenziaEntrate
#SpyNote: #APK Bancario
π£ D'eccezione
#PikaBot: Resend link ZIP