PULSE NAME
Copyright Lures Mask a Multi-Stage PureLog Stealer Attack on Key Industries
WHITE dylanroth7 2026-03-20 Modified: 2026-04-19
22
IOCs
MEDIUM VOLUME
We identified a targeted malware campaign delivering PureLog Stealer, an information‑stealing malware that uses multi‑stage packed assemblies to harvest sensitive data, including Chrome browser credentials, extensions, cryptocurrency wallets, and system information, through a file disguised as a legal copyright violation notice. It’s considered a low‑cost, easy‑to‑use infostealer, making it accessible even to less‑skilled threat actors. The attack likely relies on phishing emails that lure victims into downloading a malicious executable tailored to the victim’s local language.
Indicators of Compromise (22)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 bed2daedb43b0e5044edbabe6d1d27e8 2026-03-20
FileHash-SHA1 551e62437edab9e496ed3339f10a15cd35e3e819 2026-03-20
FileHash-SHA1 d2e8d615e7c1a810993088a8c9291e0a4a7ed4c8 2026-03-20
FileHash-SHA1 d874c3654bfb4fbf0c7c069f6e5b7ebd930415d0 2026-03-20
FileHash-SHA1 f4532fc1e5d53a732fcc883f7125ceb06b985048 2026-03-20
FileHash-SHA256 68c926af0d796a80fcaee24774b1ca0a2c393c3a0e30650c4d2d7965736043ca 2026-03-20
FileHash-SHA256 ac591adea9a2305f9be6ae430996afd9b7432116f381b638014a0886a99c6287 2026-03-20
FileHash-SHA256 e675bc054481bdca6f8cd1d561869e18712dc05a42e5c24b9add7679efc7faf6 2026-03-20
URL https://cdn.eideasrl.it/Notice%20of%20Alleged%20Violation%20of%20Intellectual%20Property%20Rights_1770380091603.zip 2026-03-20
URL https://quickdocshare.com/DQ 2026-03-20
URL https://quickdocshare.com/DQ/key 2026-03-20
URL https://transfer.af-k.de:443/webdownload?deliveryUuid=a43da640-777f-40c0-95de-64987150c869 2026-03-20
domain quickdocshare.com 2026-03-20
hostname cdn.eideasrl.it 2026-03-20
hostname dq.bestshoppingday.com 2026-03-20
hostname logs.bestsaleshoppingday.com 2026-03-20
hostname logs.bestshopingday.com 2026-03-20
hostname mh.bestshopingday.com 2026-03-20
hostname transfer.af-k.de 2026-03-20
FileHash-MD5 fd16fecedab57b025ab53ad9ca4c882f 2026-03-20
FileHash-SHA256 35efc4b75a1d70c38513b4dfe549da417aaa476bf7e9ebd00265aaa8c7295870 2026-03-20
URL http://quickdocshare.com/DQ 2026-03-20