PULSE NAME
DNS Configuration Mismatch
WHITE msudosos 2026-03-06 Modified: 2026-04-05
69
IOCs
HIGH VOLUME
DNS Configuration Mismatch: 32 entries show outbound UDP Port 53 traffic to 8.8.8.8. This traffic is non-compliant with the user-defined resolver. Unauthorized Redirection: The telemetry confirms an active bypass of local system settings, indicating either hard-coded application behavior or network-level redirection. NetBIOS Broadcast Activity: Entries for Port 137 involving 172.16.1.1 and the broadcast address 172.16.1.255 indicate internal device discovery/name registration on the local subnet. External Cloud Handshake: A single session to 52.123.250.178 via Port 443 (HTTPS) establishes an encrypted connection to Microsoft/Azure infrastructure. Anomalous Traffic Density: The high ratio of unauthorized DNS queries relative to standard web traffic (32:1) suggests a potential Command & Control (C2) beaconing or DNS tunneling profile.
Indicators of Compromise (69)
All hostname URL FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
hostname api-msn-com.ax-0003.ax-msedge.net 2026-03-06
hostname ax-0002.ax-msedge.net 2026-03-06
hostname ax-0003.ax-msedge.net 2026-03-06
hostname business-bing-com.bx-0004.bx-msedge.net 2026-03-06
hostname bx-0004.bx-msedge.net 2026-03-06
hostname edge-microsoft-com.ax-0002.ax-msedge.net 2026-03-06
hostname mr-afd-azuredge.tm-azurefd.net 2026-03-06
hostname mr-z01.tm-azurefd.net 2026-03-06
URL http://131.107.255.255 2026-03-06
hostname a-0003.a-msedge.net 2026-03-06
hostname a767.dspw65.akamai.net 2026-03-06
hostname api-msn-com-oneservice-world-default.trafficmanager.net 2026-03-06
hostname api.edgeoffer.microsoft.com 2026-03-06
hostname api.msn.com 2026-03-06
hostname atm-settingsfe-prod-geo2.trafficmanager.net 2026-03-06
hostname bingadseddgeofferapiprod-fsdbcvh7c6g2hsaf.z01.azurefd.net 2026-03-06
hostname business.bing.com 2026-03-06
hostname cac-ocsp.digicert.com.edgekey.net 2026-03-06
hostname cdn.onenote.net 2026-03-06
hostname cdn.onenote.net.edgekey.net 2026-03-06
hostname clients2.googleusercontent.com 2026-03-06
hostname config.edge.skype.com 2026-03-06
hostname config.edge.skype.com.trafficmanager.net 2026-03-06
hostname ctldl.windowsupdate.com 2026-03-06
hostname ctldl.windowsupdate.com.delivery.microsoft.com 2026-03-06
hostname download.windowsupdate.com.edgesuite.net 2026-03-06
hostname e1553.dspg.akamaiedge.net 2026-03-06
hostname e3913.cd.akamaiedge.net 2026-03-06
hostname edge-mobile-static.afd.azureedge.net 2026-03-06
hostname edge-mobile-static.azureedge.net 2026-03-06
hostname edge.microsoft.com 2026-03-06
hostname edgeassetservice.afd.azureedge.net 2026-03-06
hostname edgeassetservice.azureedge.net 2026-03-06
hostname fe3.delivery.mp.microsoft.com 2026-03-06
hostname fe3cr.delivery.mp.microsoft.com 2026-03-06
hostname glb.cws.prod.dcat.dsp.trafficmanager.net 2026-03-06
hostname glb.sls.prod.dcat.dsp.trafficmanager.net 2026-03-06
hostname googlehosted.l.googleusercontent.com 2026-03-06
hostname mira.config.skype.com 2026-03-06
hostname ocsp.digicert.com 2026-03-06
hostname ocsp.edge.digicert.com 2026-03-06
hostname oneocsp-microsoft-com.a-0003.a-msedge.net 2026-03-06
hostname oneocsp.microsoft.com 2026-03-06
hostname part-0010.t-0009.t-msedge.net 2026-03-06
hostname settings-prod-sea-1.southeastasia.cloudapp.azure.com 2026-03-06
hostname settings-win.data.microsoft.com 2026-03-06
hostname shed.dual-low.part-0010.t-0009.t-msedge.net 2026-03-06
hostname sls.update.microsoft.com 2026-03-06
hostname slscr.update.microsoft.com 2026-03-06
hostname svc.ha-teams.office.com 2026-03-06
hostname teams-mrc-ww-acdcatm.trafficmanager.net 2026-03-06
hostname teams-mrc-ww-perf.tm-4.office.com 2026-03-06
hostname update.googleapis.com 2026-03-06
hostname wu-b-net.trafficmanager.net 2026-03-06
URL https://www.youtube.com/watch 2026-03-06
FileHash-MD5 32c721a9342afe4c565ec0b7824a6bcb 2026-03-06
FileHash-SHA256 811dc17f2e570066e4e8945d4d2d256e3057815e49022f2151884c234e1bfef6 2026-03-06
URL https://www.youtube.com/watch 2026-03-06
hostname www.youtube.com 2026-03-06
FileHash-MD5 32c721a9342afe4c565ec0b7824a6bcb 2026-03-06
FileHash-SHA256 811dc17f2e570066e4e8945d4d2d256e3057815e49022f2151884c234e1bfef6 2026-03-06
URL https://www.youtube.com/watch 2026-03-06
hostname www.youtube.com 2026-03-06
hostname www.tryprojectblue.com 2026-03-06
domain trellix.com 2026-03-06
hostname www.tryprojectblue.com 2026-03-06
domain trellix.com 2026-03-06
hostname courses.tarabrach.com 2026-03-06
URL https://www.googletagmanager.com/gtag/js 2026-03-07