The TOR_LOG MIX 301PCS Stealer Log Contains 5,020 Stolen Records
HEROIC analysts identified a stealer log file named TOR_LOG MIX 301PCS circulating on Telegram, dated to June 2024. The file contains 5,020 records of endpoints, email addresses, and passwords harvested directly from infected devices.
Why the TOR_LOG MIX 301PCS Leak Is Dangerous
Stealer logs capture whatever was saved in a victim's browser at the moment of infection, so the logins inside tend to be current and working rather than stale credentials from a years-old breach. That makes this kind of file especially useful to an attacker looking for accounts they can access right now.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs
Why Stolen Logins Like These Put You at Risk
If a device was infected with the malware behind this log, whatever was saved in its browser, passwords, login pages, is now in the hands of whoever collected the log. That can lead to account takeover, credential stuffing against other accounts, and identity theft.
How a Stealer Log Like TOR_LOG MIX 301PCS Gets Made
Malware infects a device, often through cracked software, fake installers, or phishing links, then scans the browser for saved passwords, autofill data, and cookies before sending everything to an attacker-controlled server. Logs from many infected machines are bundled together and shared or sold on Telegram, with numbers like "301PCS" indicating how many victim logs are included.
Check If Your Credentials Are in the TOR_LOG MIX 301PCS Dump
HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records. Run a scan now, and if you're affected, change your passwords and scan your device for malware.
Breach Breakdown
5,020 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds