A Telegram User Posted DZ105.106.117.20 Stealer Log With 72 Plaintext Passwords
HEROIC analysts discovered a stealer log originating from the Algerian endpoint DZ105.106.117.20, uploaded to a public Telegram channel on March 15, 2025. The log contained 72 records with email addresses, plaintext passwords, and URLs taken directly from infected devices. Although smaller in scale than other stealer log leaks, the quality of the data -- real passwords in cleartext paired with their associated login URLs -- makes this highly dangerous.
Why This Is Dangerous
Attackers do not need thousands of records to do damage. With 72 complete credential sets, each linked to a specific website or service, an attacker can conduct focused account takeover attempts with a very high success rate. The plaintext passwords eliminate any need for cracking, and the URLs tell the attacker precisely where each credential works.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login pages and API endpoints)
Why This Matters
Even a small stealer log can cause outsized harm. Credential stuffing attacks are automated, so attackers can test 72 credential pairs across dozens of popular services in seconds. A single successful login can lead to account takeover, idenity theft, unauthorized purchases, or access to private communications. If any of those email addresses belong to a business account, the risks expand to include corporate data exposure and financial fraud.
How Stealer Logs Work
Infostealer malware gets onto a device through everyday actions -- clicking a bad link, running a pirated program, or opening a malicious email attachment. Once installed, it silently collects all saved browser passwords, login cookies, and autofill entries. This data is packaged and sent to a remote attacker, who then posts or sells it on Telegram. The source IP address, DZ105.106.117.20, identifies the infected machine as being located in Algeria and helps trace the origin of the harvested data.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records to tell you whether your email or password showed up in this stealer log or any other known breach. Do not wait for an attacker to discover your credentials first.
Run your free scan at HEROIC.com right now -- it only takes seconds.
Breach Breakdown
72 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds