The TOR_LOG MIX 274PCS Dump: 4,883 Stolen Credential Pairs Found
On 29-Jun-2024, HEROIC analysts identified a stealer log named TOR_LOG MIX 274PCS circulating on Telegram. The file contains 4,883 records gathered from infected devices, each including an email address, a plaintext password, and the URL of the account it belongs to.
Why This Is Dangerous
The "MIX" and "274PCS" in the file name indicate this log combines data from 274 separate infected device sessions into one file. That means an attacker gets a wide spread of unrelated victims and accounts in a single download, all with plaintext passwords ready to use.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs for each affected login
Why This Matters
Because this log blends data from hundreds of separate infections, the accounts inside it span many different people and services rather than one single target. If your credentials are among these 4,883 records, an attacker already has your working login and could use it to access other accounts if you've reused that password.
How Stealer Logs Work
Stealer logs are produced by information-stealing malware that copies saved browser passwords, autofill data, and session details from an infected device. Distributors often combine the output from many separate infections into one "mix" file, like this batch of 274 pieces, before uploading it to Telegram for sale or trade.
Check If You Are Affected
With nearly 4,900 records pulled from hundreds of separate infections, it's worth checking your exposure. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this stealer log, so you can confirm whether you're affected.
Breach Breakdown
4,883 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds