PULSE NAME
Infected Hosts - MagicSword Analytics - Alerts Merged 03.06.26
WHITE Disable_Duck 2026-03-06 Modified: 2026-04-05
815
IOCs
HIGH VOLUME
Analytics from 2 infected hosts from MagicSword Hosts are both psuedo clones (?) of a production device that connects to AHS/Covenant Health, UAlberta, Government of Alberta daily. FFSS ******https://tria.ge/260306-2134tsfs3n <- Analytic Files & a few problem Files & 'secret files' only found in Triage VM. Did not include in pulse -> 9/10 *****************
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Protection"",""internal_name"":""MpSigStub.exe"",""file_description"":""Microsoft FileExplorer Ransomware Trojan Thimeda
Indicators of Compromise (2 / 815 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL email hostname domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 deceed27caf39c2e81f6ccf82dc32efc MD5 of aeb9b61e47d91c42fff213992b7810a3d562fb12 2026-03-06
FileHash-MD5 fd2a63b8cbdcc20fd2c55e790cb563b1 MD5 of ab94c66e893012ca56de0fe8fb4deb40ea8f6da6763ee7831cc083edec50bb69 2026-03-06