ATT&CKReferencesZscaler PureCrypter JUN 2022

Zscaler PureCrypter JUN 2022

Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwarePureCrypter

PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation.

T1027.016
Junk Code Insertion
MalwarePureCrypter

PureCrypter can insert junk code to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwarePureCrypter

PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe.

T1036.008
Masquerade File Type
MalwarePureCrypter

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1055
Process Injection
MalwarePureCrypter

PureCrypter can inject its final stage into another process on the targeted system.

T1059.001
PowerShell
MalwarePureCrypter

PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete.

T1070.004
File Deletion
MalwarePureCrypter

PureCrypter can execute a PowerShell command to self-delete.

T1082
System Information Discovery
MalwarePureCrypter

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1102
Web Service
MalwarePureCrypter

PureCrypter can use Telegram or Discord to send infection status messages.

T1105
Ingress Tool Transfer
MalwarePureCrypter

PureCrypter can download additional payloads for execution on the compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwarePureCrypter

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1480
Execution Guardrails
MalwarePureCrypter

PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions.

T1480.002
Mutual Exclusion
MalwarePureCrypter

PureCrypter code contains a global mutex.

T1547.001
Registry Run Keys / Startup Folder
MalwarePureCrypter

PureCrypter can set multiple Registry Run keys to establish persistence.

T1573.002
Asymmetric Cryptography
MalwarePureCrypter

PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook.

T1614
System Location Discovery
MalwarePureCrypter

PureCrypter can use `kernel32!GetGeoInfo` to determine system location.

T1622
Debugger Evasion
MalwarePureCrypter

PureCrypter has the ability to call `CheckRemoteDebuggerPresent`.

T1673
Virtual Machine Discovery
MalwarePureCrypter

PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual.

T1678
Delay Execution
MalwarePureCrypter

PureCrypter has the ability to delay for a specified number of seconds before execution.

T1685
Disable or Modify Tools
MalwarePureCrypter

PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.