Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PureCrypter

73
Global rank
112 infographic chevron month
Month rank
107 infographic chevron week
Week rank

First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.

Loader
Type
Unknown
Origin
2 March, 2021
First seen
9 October, 2026
Last seen

How to analyze PureCrypter with ANY.RUN

Type
Unknown
Origin
2 March, 2021
First seen
9 October, 2026
Last seen

IOCs

IP addresses
184.31.95.119
2.23.231.252
2.23.231.161
2.16.168.38
48.209.138.189
40.126.31.128
52.110.17.71
23.11.41.157
23.52.181.212
74.179.77.204
131.253.33.203
172.211.123.250
2.21.239.135
188.114.96.3
48.192.1.65
157.20.182.17
2.16.204.142
92.123.104.8
184.24.77.40
23.222.81.129
Hashes
52207df335c820318cdaae9991f9a57af0601e9fe99eac755c7bd46b2cba5e25
788ed44a71fb1c147d40d853e37f19fd4edde70d2fda42fb88d02989da69ccc7
30dedb971d8a73218f523d980a435ed2434eafd69592f562c9ae00baa4f22d80
66ba37f43410293b0c702bee5b1c466372989f45f41ba5325fadbb63ab915115
fa799565324566b5c71d2523be1af4bdc786b620505c598037278036bc47c6db
4fb29c184977715008fc8449af33c68cb8882e4d9dd79659e447a498ea3a5dc7
c12e568f023cc43af97c3129a5ba4540979ec6d951f0ec2ca2066c86c20c7802
bbc30ed12f4b9528faeef2e262b650217f525dbd0f91c04829e622544cc6d7e1
7cc806171997de76b73b12a19bd5ad4f19a9c499f03e1db42341919b954f5074
4d76cdd0cc64b7df225b512c49278ba73206158f5017942185bab1fb694602cf
41089dc9ebb1b7ff6c5eb311ef031db5064f8c08f618d1081115509d7133d366
326c1636c0548032cd0c02092689b449bda8bf82c8b6eee3f5c3d81505fc3e08
f4db2f30efb36f2eed4114b5d2155d8ac444533ad26451d9b968f1a2a05a48a6
fd1e0b3a99cb016d2e7e269c2e31ec9848fb6321b4766a24cb5621e6a536b70b
f0517167fc50b5f4c27e7d1234f2f5d1ceee90961c7098300b426136e98e543d
8cf8092d89354964bf529574acadee30b0ccd4721e760faec7d0f5117751db4f
351d65fce71fe38a1bd9410a51c23ffb15ebc18d015a35cddf9f49bd5d99d3c6
af7dd3a498d9f1ea1dc81d94b1078ca2ceb2afce688d9077c54cb3995bf212cf
b58193e7486be3a383ed49b87d763be336d2201729980d29abebf082a2578616
3577ad3f933829495a1d06ac97dbfe59c4807c5da298a5bc2eece37377e31a97
Domains
ctldl.windowsupdate.com
google.com
login.live.com
fs.microsoft.com
dns.msftncsi.com
officeclient.microsoft.com
ocsp.digicert.com
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
www.microsoft.com
th.bing.com
ye.c.lencr.org
blue.ath.cx
www.bing.com
slscr.update.microsoft.com
vartk.com
ye2.c.lencr.org
x1.c.lencr.org
crl.microsoft.com
x2.c.lencr.org
URLs
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?57e293f731f65061
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?7e37aa5de4c50c28
https://fs.microsoft.com/fs/windows/config.json
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.22000.795.amd64fre.co_release.210604-1628&localdeviceid=s%3adacd04bd-5869-44da-9fd2-107288ff2e26&flightring=retail&attrdataver=183&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://www.msftconnecttest.com/connecttest.txt
https://login.live.com/rst2.srf
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.22000.795.amd64fre.co_release.210604-1628&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=183&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=261405&deviceid=s%3adacd04bd-5869-44da-9fd2-107288ff2e26&app=fss&appver=10.0&maxshellversion=1000.22000.795.0&activehoursstart=7&minshellversion=1000.22000.795.0&securebootcapable=0&activehoursend=10&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
http://158.94.211.200/st/oppugns.vbs
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=0&cvid=e11692bd0ca54132bf98a347dcaa087d&ig=0986c776e82649009130d7174b8c342c
https://th.bing.com/th?id=odswg.a63c4ede-672e-4b0b-b035-e0f9aa973fce&c=1&rs=1&p=0
https://th.bing.com/th?id=obtq.btbd45efaef9d0d3d9d98a015744bbbc0e20fe447a87bd4d5988bbcb0fdc62e822&w=204&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_a04a0b56-1c59-4267-80e3-9067d8feac2b&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_9d5a009f-e118-4b26-af30-b10cadeda865&w=140&h=96&c=1&rs=1&p=0
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 4611
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 6582
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 9728
comments 0

What is PureCrypter malware?

PureCrypter is a .NET-based loader malware first observed in March 2021. It is designed to deploy various payloads, including remote access trojans (RATs), information stealers, and other malicious tools on compromised systems. The malware is often sold on underground forums, with prices ranging from $20 to $60 per build, making it accessible to a wide range of cybercriminals.

The malware was developed by a threat actor known as PureCoder, who markets it as a customizable and reliable loader for spreading malware. PureCrypter has been linked to notable campaigns distributing AgentTesla, SnakeKeylogger, RedLine Stealer, and AsyncRAT, targeting individuals and organizations worldwide.

PureCrypter has been used in campaigns targeting financial institutions, healthcare organizations, and individual users. Its ability to deliver a wide variety of malware makes it a versatile and dangerous tool in the hands of cybercriminals.

To see how PureCrypter actually operates, you can upload its sample into ANY.RUN sandbox and check its behavior inside a secure environment.

PureCrypter analyzed inside ANY.RUN sandbox PureCrypter analyzed inside ANY.RUN sandbox

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

PureCrypter malware technical details

The primary functionalities and features of PureCrypter include:

  • Deploys various malware types such as AgentTesla, SnakeKeylogger, RedLine Stealer, and AsyncRAT.
  • Uses SmartAssembly to obfuscate its code, making it difficult for antivirus tools to detect.
  • Encrypts and compresses payloads to conceal malicious activities during delivery.
  • Injects payloads into legitimate processes to bypass security measures and evade detection.
  • Ensures continued presence on the infected system through registry modifications and startup entries.
  • Sold on underground forums with options for customization, making it accessible to cybercriminals with varying technical expertise.
  • Delivered via phishing campaigns with malicious attachments (e.g., disguised .mp4, .pdf, or executable files).

Often used in campaigns against financial, healthcare, and individual targets globally.

PureCrypter malware execution process

To see how PureCrypter operates, let’s upload its sample to the ANY.RUN sandbox.

PureCrypter typically spreads through malicious downloads or phishing attacks. Once a user executes the infected file, the malware begins its execution chain. Upon execution, PureCrypter decrypts its payload in memory to avoid leaving traces on the disk, making it harder for traditional antivirus solutions to detect. The decrypted payload is then injected into a legitimate system process, helping the malware blend in with normal system activities and further evade detection.

In our case, the targeted process is MSBuild, but PureCrypter may also inject into other legitimate system processes, such as InstallUtil.

Malicious process displayed in ANY.RUN sandbox Malicious process displayed in ANY.RUN sandbox

In addition to process injection, PureCrypter leverages various trusted system tools. For example, in this scenario, it ran PowerShell to add Product.exe and its associated processes to the antivirus exclusion list, reducing the likelihood of detection.

Process tree of PureCrypter analysis inside ANY.RUN Process tree of PureCrypter analysis inside ANY.RUN

After establishing itself within a legitimate process, PureCrypter connects to its command-and-control (C2) server. Through this connection, attackers can issue commands, download additional payloads, or exfiltrate data from the infected machine. Ultimately, PureCrypter executes its primary malicious payload, which can range from ransomware or spyware to other forms of malware designed to steal data or compromise the system.

To ensure persistence after a reboot, PureCrypter may modify registry entries, create scheduled tasks, or use other persistence techniques. It can also self-delete after execution to erase evidence of its presence.

MITRE ATT&CK sub-technique identified by ANY.RUN sandbox MITRE ATT&CK sub-technique identified by ANY.RUN sandbox

In our example, the injected MSBuild process ran the Command Prompt (CMD) to terminate itself and remove the initial Product.exe file.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gathering Threat Intelligence on PureCrypter Malware

To collect up-to-date intelligence on PureCrypter, use Threat Intelligence Lookup.

This service provides access to a vast database with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 customizable search parameters, users can gather detailed data on threats, including IPs, domains, file names, and process artifacts.

Search results for PureCrypter in Threat Intelligence Lookup Search results for PureCrypter in Threat Intelligence Lookup

For instance, to investigate PureCrypter, you can search by its threat name or use a related artifact. A query like threatName:"PureCrypter" will retrieve all associated samples and sandbox results relevant to this loader malware.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

PureCrypter is a dangerous malware capable of deploying various threats while evading detection through obfuscation and encryption. Tools like ANY.RUN can help to analyze suspicious files and URLs to prevent attacks.

ANY.RUN offers real-time malware analysis with features like visual execution chains and script tracing, helping users detect threats effectively.

Sign up for a free ANY.RUN account today and analyze unlimited malware attacks!

HAVE A LOOK AT

Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Godfather screenshot
Godfather
godfather
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
Read More