← Back to SOC feed Coverage →

ThreatFox: PureLogs Stealer IOCs

ioc-hunt HIGH ThreatFox
CommonSecurityLogDeviceNetworkEvents
infostealeriocthreatfoxwin-purelogs
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-04T11:00:00Z · Confidence: high

Hunt Hypothesis

This detection identifies adversary activity involving the PureLogs Stealer by monitoring for six specific indicators of compromise that signal potential credential and data theft within the environment. A proactive hunt is essential in Azure Sentinel to rapidly identify and isolate infected endpoints before attackers can exfiltrate sensitive information or establish persistent access.

IOC Summary

Malware Family: PureLogs Stealer Total IOCs: 6 IOC Types: ip:port

TypeValueThreat TypeFirst SeenConfidence
ip:port64[.]89[.]160[.]76:8443botnet_cc2026-08-0475%
ip:port64[.]89[.]160[.]76:8288botnet_cc2026-08-0475%
ip:port64[.]89[.]160[.]76:9508botnet_cc2026-08-0475%
ip:port64[.]89[.]160[.]76:465botnet_cc2026-08-0475%
ip:port185[.]242[.]3[.]65:9001botnet_cc2026-08-0475%
ip:port65[.]21[.]212[.]79:62020botnet_cc2026-08-0475%

KQL: Ip Hunt

// Hunt for network connections to known malicious IPs
// Source: ThreatFox - PureLogs Stealer
let malicious_ips = dynamic(["185.242.3.65", "64.89.160.76", "65.21.212.79"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc

KQL: Ip Hunt Device

// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["185.242.3.65", "64.89.160.76", "65.21.212.79"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DeviceNetworkEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the ThreatFox: PureLogs Stealer IOCs detection rule, including targeted filters and exclusions tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/win.purelogs/