PULSE NAME
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
WHITE AlienVault 2026-05-26 Modified: 2026-05-27
12
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign distributes a PureLogs variant through deceptive purchase order emails containing malicious JavaScript files. The attack chain employs obfuscated JavaScript that drops PowerShell scripts, which then use process hollowing techniques to inject .NET modules into legitimate Windows processes. The malware communicates with command-and-control infrastructure to download additional plugins. PureLogs collects extensive sensitive information including credentials from web browsers, cryptocurrency wallets, email clients, Discord, and various applications. It also captures screenshots, system information, and clipboard data. The collected data is compressed, encrypted with AES, and exfiltrated to remote servers. The campaign demonstrates advanced evasion techniques through fileless execution, multiple encryption layers, and abuse of trusted processes like MsBuild.exe, making detection challenging for traditional security solutions.
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6af99d08e9295db93ad869af5ec1422e 2026-05-26
FileHash-MD5 e2470b4bb66131ac43a0e7d30bb30ede 2026-05-26
FileHash-SHA1 4f2c2a808194d27992ef227c4b9134de01d051fc 2026-05-26
FileHash-SHA1 cda7136e67b34757ef2688f1e168fc927f025625 2026-05-26
FileHash-SHA256 07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841 2026-05-26
FileHash-SHA256 3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5 2026-05-26
FileHash-SHA256 670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92 2026-05-26
FileHash-SHA256 b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173 2026-05-26
FileHash-SHA256 e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95 2026-05-26
IPv4 77.83.39.211 2026-05-26
URL https://77.83.39.211:8443/application 2026-05-26
URL https://77.83.39.211:8443/filesearch/req 2026-05-26