← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
A sophisticated phishing campaign distributes a PureLogs variant through deceptive purchase order emails containing malicious JavaScript files. The attack chain employs obfuscated JavaScript that drops PowerShell scripts, which then use process hollowing techniques to inject .NET modules into legitimate Windows processes. The malware communicates with command-and-control infrastructure to download additional plugins. PureLogs collects extensive sensitive information including credentials from web browsers, cryptocurrency wallets, email clients, Discord, and various applications. It also captures screenshots, system information, and clipboard data. The collected data is compressed, encrypted with AES, and exfiltrated to remote servers. The campaign demonstrates advanced evasion techniques through fileless execution, multiple encryption layers, and abuse of trusted processes like MsBuild.exe, making detection challenging for traditional security solutions.
MITRE ATT&CK & Malware Families
Indicators of Compromise (12)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 6af99d08e9295db93ad869af5ec1422e | — | 2026-05-26 | |
| FileHash-MD5 | e2470b4bb66131ac43a0e7d30bb30ede | — | 2026-05-26 | |
| FileHash-SHA1 | 4f2c2a808194d27992ef227c4b9134de01d051fc | — | 2026-05-26 | |
| FileHash-SHA1 | cda7136e67b34757ef2688f1e168fc927f025625 | — | 2026-05-26 | |
| FileHash-SHA256 | 07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841 | — | 2026-05-26 | |
| FileHash-SHA256 | 3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5 | — | 2026-05-26 | |
| FileHash-SHA256 | 670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92 | — | 2026-05-26 | |
| FileHash-SHA256 | b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173 | — | 2026-05-26 | |
| FileHash-SHA256 | e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95 | — | 2026-05-26 | |
| IPv4 | 77.83.39.211 | — | 2026-05-26 | |
| URL | https://77.83.39.211:8443/application | — | 2026-05-26 | |
| URL | https://77.83.39.211:8443/filesearch/req | — | 2026-05-26 |