Top Tweets for #PureCrypter
Do #PureLogs Stealer and #PureCrypter use the same C2 protocol, or is there some way to tell the C2 protocols apart?
C2 servers:
🔥 45.141.233.100:7708
🔥 144.172.91.74:7709
🔥 62.60.235.100:9100
🔥 65.108.24.103:62050
🔥 91.92.120.102:62050
🔥 192.30.240.242:62520

Blog on #PureCrypter just dropped! Included is a tool to automate the unpacking process, decrypt strings, and dump the Protobufs-based malware configuration. There's also countless screenshots for those interested in how it works!
https://t.co/slZgpdYTrw

Blog on #PureCrypter just dropped! Included is a tool to automate the unpacking process, decrypt strings, and dump the Protobufs-based malware configuration. There's also countless screenshots for those interested in how it works!
https://t.co/slZgpdYTrw

🚨#Opendir #Malware🚨
hxxp://sappycloud.org/
⚠️#Purecrypter
☣️Nigga.exe➡️186d294e74367b1199a81aa71c43dd06
📡45.88.186.38:7232
⚠️#Xworm
☣️folk.bat➡️a2daabff36b8da27747593cf1d93b244
📡176.65.144.116:7232
⚠️Bat script 📸⤵️
☣️road.bat➡️303dfee95d4f85509c55c5a95bfe7e78

Some #serbian gov domains compromised and attacking #hungarian government facilities and organisations, using compromised croatian websites for next stage.
#PureCrypter sample from today:
https://t.co/3euglPfiN5
EXE: https://t.co/QC4NQyWT6d
@JAMESWT_MHT
Netskope's Leandro Fróes looks into a global malware campaign using fake CAPTCHAs to deliver Lumma Stealer. The infection chain includes a step where the attacker asks the victim to execute a command from their clipboard using the Windows Run command. https://t.co/9izapkorM3

uncrypted,exe seems to use #LimeCrypter (https://t.co/Mdm4lPxSpp) to load final #DarkVisionRat stored in resources and decrypted with rfc2898DeriveBytes AES function. Previously it was used with #PureCrypter as detected by @Threatlabz https://t.co/tWdBP6eJNJ

![lontze7's tweet photo. #DarkVisionRAT #opendir
https://5.89.185[.]156/ https://t.co/CeGsnE6PBC](https://pbs.twimg.com/media/GgG-TDSXcAAo3Mt.png)
🚨 #PureCrypter is a stealthy loader malware actively distributing threats like #AgentTesla, #RedLine stealer, and #SnakeKeylogger
It disguises malicious files as videos or documents
Learn more and gather #IOCs & samples
👉 https://t.co/zAYiWqhCyh

#malspam containing .bat attachment with embedded #purecrypter dropping #redline stealer
C2: 104.168.34.185:2819
https://t.co/NXkyh2Bjtp
Zscaler ThreatLabz uncovered a malware campaign using #DarkVision RAT alongside #PureCrypter and #DonutLoader. Our blog covers the attack chain as well as a technical analysis of DarkVision RAT including its persistence, network communication protocol, plugins, and commands.
Link: https://t.co/D7abpnCxFL

@malwrhunterteam Related
#purecrypter #pureminer #netreactor
❇️https://t.co/L9G1ZogBpZ
❇️https://t.co/ScTYt1WQxi
#ThreatProtection #PureCrypter #malware used in #Mallox #ransomware distribution campaign, read more about Symantec's protection: https://t.co/WRGSGLcUeY
MS-SQL ハニーポット攻撃を介して展開される Mallox ランサムウェア
Mallox Ransomware Deployed Via MS-SQL Honeypot Attack #InfoSecurityMagazine (May 13)
#Mallox #MS-SQL #ランサムウェア #ブルートフォース #PureCrypter
https://t.co/7ywihGjegK
#PureLogs is a stealer belonging to the Pure #malware family 🏴☠️
Delivered by the #PureCrypter loader, it steals browser data, crypto wallets, and even files.
Learn more & collect its #IOCs/samples
➡️ https://t.co/3UPqQd1pFS

🚨 We made a complete breakdown of the #Pure malware family
Pure is sophisticated #malware that's gaining popularity. It features #PureCrypter, a powerful stealer #PureLogs, and as we discovered — a miner.
There's a lot of ground to cover. Let's dive in: https://t.co/2QOwlpTLts
#100DaysofYara Day 9:
Excited to get this one in. Today we will cover the rules for the latest #PureCrypter's initial and core payloads. PureCrypter is a .NET crypter/loader, which has been used by many RATs and stealers.
It also means another contribution to #UnprotectProject , cc @fr0gger_ 💜
PureCrypter initial payload: https://t.co/oigDnbonvT
PureCrypter core payload: https://t.co/XiMefVWiql

296adaf28851028d68715c7e5f29326215d114feec70cb10ac123881c2edabd6 https://t.co/z7SzFo81xQ #purelogs #purecrypter #loader #stealer @anyrun_app
@karol_paciorek @500mk500 @g0njxa @JAMESWT_MHT @malwrhunterteam @executemalware Most likely #PureCrypter payloads.
Last Seen Hashtags on Sotwe
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.3M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.5M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.4M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.7M followers

KATY PERRY 
@katyperry
87.1M followers

Taylor Swift 
@taylorswift13
80.9M followers

Lady Gaga 
@ladygaga
72.5M followers

Kim Kardashian 
@kimkardashian
69.5M followers

Virat Kohli 
@imvkohli
69M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.6M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.6M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.2M followers












![lontze7's tweet photo. #DarkVisionRAT #opendir
https://5.89.185[.]156/ https://t.co/CeGsnE6PBC](https://pbs.twimg.com/media/GgG9dWiWMAAF5pV.png)
![lontze7's tweet photo. #DarkVisionRAT #opendir
https://5.89.185[.]156/ https://t.co/CeGsnE6PBC](https://pbs.twimg.com/media/GgG9QYtWQAAhz6s.jpg)
![lontze7's tweet photo. #DarkVisionRAT #opendir
https://5.89.185[.]156/ https://t.co/CeGsnE6PBC](https://pbs.twimg.com/media/GgG9CvBWUAAtQ_w.png)











