Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with PureLogStealer

Database Entry


Malware:PureLogStealer
First seen:2024-03-15 22:01:56 UTC
Last seen:2024-04-15 09:05:56 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2024-04-15 09:05:5627f8736302cc341a6fee7eef31efa585Virustotal results 42 / 69 (60.87%) PureLogStealer157.90.25.39:5432
2024-04-09 01:22:087557af6f3185128c25aeb092dc335975Virustotal results 51 / 72 (70.83%) PureLogStealer45.11.229.96:56001
2024-04-05 23:58:39a8fd283b496ea064535eaf1df71af3dfVirustotal results 53 / 72 (73.61%) PureLogStealer185.125.50.121:56001
2024-04-05 23:58:39a8fd283b496ea064535eaf1df71af3dfVirustotal results 53 / 72 (73.61%) PureLogStealer185.125.50.121:56001
2024-03-28 21:46:50eb938b04b9b1b655342306bf3987a6efn/aPureLogStealer91.92.243.85:56001
2024-03-26 01:49:08f76cb49209891942d2ca806020803edcVirustotal results 42 / 73 (57.53%) PureLogStealer194.62.248.64:56001
2024-03-17 06:10:307b9611d8a0144297915006d6c4a8439fVirustotal results 43 / 73 (58.90%) PureLogStealer91.92.252.228:56001
2024-03-15 22:01:563e054dc83f96399848ce95ad93d017b5Virustotal results 39 / 73 (53.42%) PureLogStealer93.123.39.28:8075