PureLogs Payload PE with Hashed API Resolution & XOR/RC4 String Obfuscation
Detects PureLogs Stealer payload binaries by identifying specific artifacts including a hardcoded nibble-decoding alphabet, minimal PE imports, and high-entropy sections containing obfuscated Windows API strings like GetProcAddress, kernel32.dll, and ntdll.dll.
YARA

