PULSE NAME
vxCube — Report
WHITE msudosos 2026-04-26 Modified: 2026-05-26
264
IOCs
HIGH VOLUME
[Researchers have identified the first "pulses" to be created on a single domain, the GoDaddy.com, and the second to have been identified by its owner, a US company.] Date - 2024-12-10 11:15:23 UTC for [017076655d1d5d05656azcb!z] [exe parent of>] and [4ca5bc812211957dc963d03fc773d01d9b6643c4d99d31a9f9032fcbed39cf9c, 2025-06-02 05:00:56 UTC]
Indicators of Compromise (3 / 264 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname email CVE
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2018-1000861 A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way. 2026-04-26
CVE CVE-2014-0160 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug. 2026-04-26
CVE CVE-2020-11652 An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. 2026-04-26