PULSE NAME
Update 1: Water Saci: WhatsApp-Driven SORVEPOTEL Malware Targets Brazilian Enterprises
WHITE SOC__critical43 2025-11-20 Modified: 2025-12-20
25
IOCs
MEDIUM VOLUME
Indicators of Compromise (25)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 20d9ad0ff3375fa5916f0cabf321485b 2025-11-20
FileHash-MD5 211bab3c481245005fbad0ea8bc6dd77 MD5 of d2e7f3dff732748d3cf2d415600b81ab67b6a404 2025-11-20
FileHash-MD5 22fd7c48d91fd9fcda9c1c1a2b51c540 MD5 of 835478d00945db56658a5f694f4ac9f5d49930db 2025-11-20
FileHash-MD5 d060b78ee36e99533005dfb80c8137d1 MD5 of 8fd64b79a7d2b5c7c21d197c4852f10ac6f52536 2025-11-20
FileHash-SHA1 835478d00945db56658a5f694f4ac9f5d49930db 2025-11-20
FileHash-SHA1 8fd64b79a7d2b5c7c21d197c4852f10ac6f52536 2025-11-20
FileHash-SHA1 c675cd66d2d516249034ffa15b4a66de5a15692e 2025-11-20
FileHash-SHA1 d2e7f3dff732748d3cf2d415600b81ab67b6a404 2025-11-20
FileHash-SHA256 06ddb29639e875fed71185e02fd477964e2aab0082f923ac36533a86a4c56e53 SHA256 of 8fd64b79a7d2b5c7c21d197c4852f10ac6f52536 2025-11-20
FileHash-SHA256 77ea1ef68373c0dd70105dea8fc4ab41f71bbe16c72f3396ad51a64c281295ff SHA256 of 835478d00945db56658a5f694f4ac9f5d49930db 2025-11-20
FileHash-SHA256 c50b6ff360e5614d91f80a5e2d616a9d0d1a9984751bf251f065426a63dac0b5 SHA256 of d2e7f3dff732748d3cf2d415600b81ab67b6a404 2025-11-20
FileHash-SHA256 d00afb9fd2ae69a4763902ebca80bf5afd9a667549919425beb21090f8c8df37 2025-11-20
URL https://zapgrande.com/api/itbi/BrDLwQ4tU70zZUeEHSSimym64kqXVG39 2025-11-20
domain adoblesecuryt.com 2025-11-20
domain bravexolutions.com 2025-11-20
domain cmqsqomiwwksmcsw.xyz 2025-11-20
domain etenopote.com 2025-11-20
domain expahnsiveuser.com 2025-11-20
domain saogeraldoshoping.com 2025-11-20
domain sorvetenoopote.com 2025-11-20
domain sorvetenopoate.com 2025-11-20
domain sorvetenopotel.com 2025-11-20
domain ykgmqooyusggyyya.xyz 2025-11-20
domain zapgrande.com 2025-11-20
hostname sorv.etenopote.com 2025-11-20