static-urls · Crawled Jul 31, 2026

PureLogs, PureRAT and misleading zgRAT

12 IoCs 1 Malware
Read original article ↗

AI Summary

The article clarifies confusion between malware families attributed to developer PureCoder, specifically distinguishing PureLogs, an infostealer, from PureRAT, a Remote Access Trojan (RAT). Both are .NET-based and have been mislabeled as zgRAT in detection rules, leading to false positives. The article provides technical indicators and Suricata signatures for detecting PureLogs and PureRAT, emphasizing the importance of accurate classification to avoid misattribution.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 12 extracted

Type Value Detail
IP 204[.]44[.]93[.]88 Details →
IP 5[.]101[.]84[.]75 Details →
IP 46[.]151[.]182[.]159 Details →
IP 85[.]239[.]149[.]178 Details →
IP 196[.]251[.]107[.]6 Details →
IP 45[.]192[.]211[.]59 Details →
MD5 404f0d36fcbe5c4643e821403a4827eb Details →
MD5 7e49bac468548a0e83133f0d5b02544b Details →
MD5 3c9852c53cb45221886b34ed6bc7d674 Details →
MD5 323fed78fc8aaa86c3d35aa85313645d Details →
MD5 b4400998cf293b0767455fb37526b18e Details →
MD5 010301d23beacee631006245ed09a2f7 Details →