PULSE NAME
DNS Configuration Mismatch
WHITE msudosos 2026-03-06 Modified: 2026-04-05
69
IOCs
HIGH VOLUME
DNS Configuration Mismatch: 32 entries show outbound UDP Port 53 traffic to 8.8.8.8. This traffic is non-compliant with the user-defined resolver. Unauthorized Redirection: The telemetry confirms an active bypass of local system settings, indicating either hard-coded application behavior or network-level redirection. NetBIOS Broadcast Activity: Entries for Port 137 involving 172.16.1.1 and the broadcast address 172.16.1.255 indicate internal device discovery/name registration on the local subnet. External Cloud Handshake: A single session to 52.123.250.178 via Port 443 (HTTPS) establishes an encrypted connection to Microsoft/Azure infrastructure. Anomalous Traffic Density: The high ratio of unauthorized DNS queries relative to standard web traffic (32:1) suggests a potential Command & Control (C2) beaconing or DNS tunneling profile.
Indicators of Compromise (2 / 69 total)
All hostname URL FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 32c721a9342afe4c565ec0b7824a6bcb 2026-03-06
FileHash-MD5 32c721a9342afe4c565ec0b7824a6bcb 2026-03-06