static-urls · Crawled Jul 31, 2026
PureLogs, PureRAT and misleading zgRAT
12 IoCs 1 Malware
Read original article ↗
AI Summary
The article clarifies confusion between malware families attributed to developer PureCoder, specifically distinguishing PureLogs, an infostealer, from PureRAT, a Remote Access Trojan (RAT). Both are .NET-based and have been mislabeled as zgRAT in detection rules, leading to false positives. The article provides technical indicators and Suricata signatures for detecting PureLogs and PureRAT, emphasizing the importance of accurate classification to avoid misattribution.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 204[.]44[.]93[.]88 | Details → |
| IP | 5[.]101[.]84[.]75 | Details → |
| IP | 46[.]151[.]182[.]159 | Details → |
| IP | 85[.]239[.]149[.]178 | Details → |
| IP | 196[.]251[.]107[.]6 | Details → |
| IP | 45[.]192[.]211[.]59 | Details → |
| MD5 | 404f0d36fcbe5c4643e821403a4827eb | Details → |
| MD5 | 7e49bac468548a0e83133f0d5b02544b | Details → |
| MD5 | 3c9852c53cb45221886b34ed6bc7d674 | Details → |
| MD5 | 323fed78fc8aaa86c3d35aa85313645d | Details → |
| MD5 | b4400998cf293b0767455fb37526b18e | Details → |
| MD5 | 010301d23beacee631006245ed09a2f7 | Details → |