301 Files, 4,238 Records: Inside the TOR_LOG MIX Stealer Dump
HEROIC analysts identified a stealer log file labeled "TOR_LOG MIX 301PCS" uploaded to Telegram on 10 June 2024. The file contained 4,238 records combining endpoints, email addresses, API hosts, and plaintext passwords, pulled together from roughly 301 individual infected devices into one combined dump. Unlike a single-source breach, this file represents malware output collected from many different victims at once.
Why This Is Dangerous
Because the passwords are plaintext and paired directly with the URLs and hosts they unlock, an attacker does not need to guess or crack anything. Stealer logs like this also often reveal a victim's full login pattern across multiple sites, giving an attacker a roadmap of every account tied to that device, not just one password.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs and API hosts
Why This Matters
Because stealer logs capture credentials directly from an infected device, the accounts inside tend to be currently active and correctly paired, which makes them especially useful to attackers running credential stuffing attacks. With over 4,200 records spanning 301 separate logs, the combined dataset raises the risk of account takeover, identity theft, and financial fraud across many unrelated services at once.
How Stealer Logs Work
A stealer log is the output of information-stealing malware that infects a device and silently harvests saved passwords, browser cookies, and autofill data, then sends it back to the attacker. A "MIX" file like this one combines logs from many separate infections, in this case around 301, into a single package for resale or free distribution on platforms like Telegram. Unlike a combolist built from old breach data, a stealer log reflects credentials as they existed on the victim's device at the moment of infection, which is part of why they are considered especially fresh and dangerous.
Check If You Are Affected
If you want to know whether your credentials appear in this or any other leaked dataset, HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records in seconds and shows you what to do next if you are exposed.
Breach Breakdown
4,238 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds