PULSE NAME
VirusTotal Box of Apples Sandbox report
WHITE msudosos 2026-03-08 Modified: 2026-04-07
35
IOCs
MEDIUM VOLUME
creep.
Indicators of Compromise (35)
All FileHash-SHA256 domain URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 004adf62746e56b097d3f5885006bd185ffc002bcd960e3eea1ce652fb1893f4 2026-03-08
domain mdworker.sb 2026-03-08
URL http://client.sh 2026-03-08
domain bootstrap.py 2026-03-08
domain client.py 2026-03-08
domain execute.py 2026-03-08
domain launcher.py 2026-03-08
domain report.py 2026-03-08
domain vt.py 2026-03-08
domain wrapper.py 2026-03-08
hostname com.google.box 2026-03-08
FileHash-SHA256 004adf62746e56b097d3f5885006bd185ffc002bcd960e3eea1ce652fb1893f4 2026-03-08
domain mdworker.sb 2026-03-08
URL http://client.sh 2026-03-08
domain bootstrap.py 2026-03-08
domain client.py 2026-03-08
domain execute.py 2026-03-08
domain launcher.py 2026-03-08
domain report.py 2026-03-08
domain vt.py 2026-03-08
domain wrapper.py 2026-03-08
hostname com.google.box 2026-03-08
FileHash-SHA256 004adf62746e56b097d3f5885006bd185ffc002bcd960e3eea1ce652fb1893f4 2026-03-08
domain mdworker.sb 2026-03-08
URL http://client.sh 2026-03-08
domain bootstrap.py 2026-03-08
domain client.py 2026-03-08
domain execute.py 2026-03-08
domain launcher.py 2026-03-08
domain report.py 2026-03-08
domain vt.py 2026-03-08
domain wrapper.py 2026-03-08
hostname com.google.box 2026-03-08
URL https://mwdb.cert.pl/file/004adf62746e56b097d3f5885006bd185ffc002bcd960e3eea1ce652fb1893f4 2026-03-08
URL https://support.apple.com/en-us/103272 2026-03-09