MALICIOUS — 070181f442b486e6bc3192434f99c19bff30441fdc069a2274987d742178c2ec.exe
MALICIOUS — 070181f442b486e6bc3192434f99c19bff30441fdc069a2274987d742178c2ec.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the PureLogStealer family. 7 of 53 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
070181f442b486e6bc3192434f99c19bff30441fdc069a2274987d742178c2ec - SHA-1:
d2adac82d0821c8590dd95599abd5bd1e43ff1d8 - MD5:
21fb6930c2679a056a8cfd79f93f53cd - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:VOBkAAB9XyH8KM/0uQ3cxaIdChRLJtRtYLZHudMa0Y/k9fMgnsbhE:hXk8KMMuzojtRtydHY/k97si - TLSH:
T11650BF59CA18981FFCBC641F2CA58AAE19CD4F5F343D6461506BD3B67F222A3422109F - Submitted as: 070181f442b486e6bc3192434f99c19bff30441fdc069a2274987d742178c2ec.exe
- File type: pe · Size: 827392 bytes
- Verdict: malicious (100/100) · Family: PureLogStealer
Source: MalwareBazaar · first seen 2026-07-28T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:MSIL/PureLogStealer.RVG!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.Mardom.MN.9
- Kaspersky (KVRT): HEUR:Trojan-Spy.MSIL.Bobik.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in svchost.exe (pid 912) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:MSIL/PureLogStealer.RVG!MTB (rule
Trojan:MSIL/PureLogStealer.RVG!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.Mardom.MN.9 (rule
Gen:Trojan.Mardom.MN.9) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
15055 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- desktop-hsgcbep
- config.edge.skype.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- watson.events.data.microsoft.com
- dns.msftncsi.com
- g.live.com
- ecs.office.com
- self.events.data.microsoft.com
- edge.microsoft.com
- aefd.nelreports.net
- www.msftncsi.com
- time.windows.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- 44ab08122aa51913d6dc289609c73727baf64c17e0dcbd5cbcc319182a2c2cf9 -
44ab08122aa51913d6dc289609c73727baf64c17e0dcbd5cbcc319182a2c2cf9 - f85c577da95d7d8ce00c7913443087f39298dc3e0b9c5efc1626113df7c68fca -
f85c577da95d7d8ce00c7913443087f39298dc3e0b9c5efc1626113df7c68fca - b46a5b28828984e86f832be5638ce069a9b718444a491655fd1a2cdb933cfc09 -
b46a5b28828984e86f832be5638ce069a9b718444a491655fd1a2cdb933cfc09 - c23bd7368754272fe53cea1d785fad32bfbe7d41bc31050b3c6b1b152c38044f -
c23bd7368754272fe53cea1d785fad32bfbe7d41bc31050b3c6b1b152c38044f - 67dd78e6f39fdc0b7fbb87e56e1511f8236732df8297f4895185968326096c45 -
67dd78e6f39fdc0b7fbb87e56e1511f8236732df8297f4895185968326096c45 - b2a66e9864f81c2800a5afef4bfd1faf7c910e5a43ea2eb9dbb15c8ab6ffc633 -
b2a66e9864f81c2800a5afef4bfd1faf7c910e5a43ea2eb9dbb15c8ab6ffc633
Embedded domains
- aefd.nelreports.net
Embedded IP addresses
- 204.44.93.88
More PureLogStealer samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report