PULSE NAME
CAPE Sandbox
WHITE msudosos 2026-03-07 Modified: 2026-04-06
64
IOCs
HIGH VOLUME
ROOTKiTBOOTKIT=complete attack of identity
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (64)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 53f9f78f4f86c2e5f98946f6aa5027ad 2026-03-07
FileHash-MD5 6fe5df9477ea917a7c680d08416bd735 2026-03-07
FileHash-SHA1 058243d5b687ecd20d37491e83279b0f6d86cf0c 2026-03-07
FileHash-SHA1 ee223d2e7d82d1cd0942f6f3de24a6dd174f0397 2026-03-07
FileHash-SHA256 05a31f3fcc85ca7945efb2380e6922352afb89cb5396db231f94db7f0d8a74a5 2026-03-07
FileHash-SHA256 8a390298839191beaf4276ce2e86d5a9bec157721cd2d02b64b19376e38c7abb 2026-03-07
domain this.ca 2026-03-07
hostname api-msn-com.ax-0003.ax-msedge.net 2026-03-07
hostname array.prototype.slice.call 2026-03-07
hostname ax-0003.ax-msedge.net 2026-03-07
hostname microsoft.windows.search 2026-03-07
hostname object.prototype.hasownproperty.call 2026-03-07
hostname object.prototype.tostring.call 2026-03-07
domain a.ie 2026-03-07
domain ca.call 2026-03-07
domain disallowedcertstl.cab 2026-03-07
domain e.sd 2026-03-07
domain jquery.org 2026-03-07
domain pinrulesstl.cab 2026-03-07
hostname a-0003.a-msedge.net 2026-03-07
hostname a767.dspw65.akamai.net 2026-03-07
hostname api-msn-com-oneservice-world-default.trafficmanager.net 2026-03-07
hostname api.msn.com 2026-03-07
hostname atm-settingsfe-prod-geo2.trafficmanager.net 2026-03-07
hostname bg.microsoft.map.fastly.net 2026-03-07
hostname cac-ocsp.digicert.com.edgekey.net 2026-03-07
hostname cdn.onenote.net 2026-03-07
hostname cdn.onenote.net.edgekey.net 2026-03-07
hostname ctldl.windowsupdate.com 2026-03-07
hostname ctldl.windowsupdate.com.delivery.microsoft.com 2026-03-07
hostname dns.msftncsi.com 2026-03-07
hostname download.windowsupdate.com.edgesuite.net 2026-03-07
hostname e1553.dspg.akamaiedge.net 2026-03-07
hostname e16604.dscf.akamaiedge.net 2026-03-07
hostname e3913.cd.akamaiedge.net 2026-03-07
hostname fe3.delivery.mp.microsoft.com 2026-03-07
hostname fe3cr.delivery.mp.microsoft.com 2026-03-07
hostname fs-wildcard.microsoft.com.edgekey.net 2026-03-07
hostname fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net 2026-03-07
hostname fs.microsoft.com 2026-03-07
hostname glb.cws.prod.dcat.dsp.trafficmanager.net 2026-03-07
hostname glb.sls.prod.dcat.dsp.trafficmanager.net 2026-03-07
hostname ocsp.digicert.com 2026-03-07
hostname ocsp.edge.digicert.com 2026-03-07
hostname oneocsp-microsoft-com.a-0003.a-msedge.net 2026-03-07
hostname oneocsp.microsoft.com 2026-03-07
hostname prod.fs.microsoft.com.akadns.net 2026-03-07
hostname settings-prod-uks-2.uksouth.cloudapp.azure.com 2026-03-07
hostname settings-win.data.microsoft.com 2026-03-07
hostname sls.update.microsoft.com 2026-03-07
hostname slscr.update.microsoft.com 2026-03-07
hostname time.windows.com 2026-03-07
hostname twc.trafficmanager.net 2026-03-07
hostname wu-b-net.trafficmanager.net 2026-03-07
URL http://131.107.255.255 2026-03-07
URL http://disallowedcertstl.cab?112260603cefe41a 2026-03-07
URL http://disallowedcertstl.cab?34ced728425920ae 2026-03-07
URL http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?112260603cefe41a 2026-03-07
URL http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?34ced728425920ae 2026-03-07
URL http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?d8e14a6e6e4d03fb 2026-03-07
URL http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsMayxGaRewR3PGR9SvwMg%3D 2026-03-07
URL http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBR0TBEVYklX7A9yLoLD9hqmCWDxFgQU3pGGSLehMVkx8UtfB6nciHnaqHYCEzMAAAAPMyBlN%2B5Crk8AAAAAAA8%3D 2026-03-07
URL http://jquery.org/license. 2026-03-07
URL http://pinrulesstl.cab?d8e14a6e6e4d03fb 2026-03-07