PULSE NAME
Enemy of the State: Order in the Court • Part 4 - World Media
WHITE Q.Vashti 2026-04-27 Modified: 2026-05-27
5051
IOCs
HIGH VOLUME
Critical, out of control targeting. Suspected Pegasus related campaign seen in State of Colorado court and Hospital systems+++. The answer is NO. The crime victim / survivor was never going to be given a chance to bring forward a case of any type of. Silenced. Not allowed to pursue justice. Car accident. No. Robbed. No Assault. No. Either the State is heavily involved or systems are manipulated by adversaries. CVE found more than a year ago, Original OTX researchers Pulses not found. CVE Overview: In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
wifi idaprilextractionenter sctype oldata uploadextrareferenwifi datawifintgraph xedynamicloaderhighporta8 f0c0 a0c4 d8a4 c4cacheyara rulewritemusicexplorerguardtrackermediadefaultfileid loginmwdbbazaarsha3384ssdeepxportacceptagentshutdownpe filenetwork infosampleaslrprogrammitre attackprocesses extraoverview zenboxverdictiocsextra dataincluded iocsindicatorreview iocsfinddr wifiinclude reviewexclude suggesfind sfailedtyp urlregistrant nameall domainpassive dnsurlsfilesaccessall ipv4america flagdes moineslevelzeppelindomain addunited statesactivemsiewindows ntunitedsearchmediumas16509unknownupatremalwarenextip addresspty ltdurl analysistrojanwrite csuspicioustt trultradns clientservicename serversemailsworld mediacontactedpostu001b4nu0017powershellsc datatypeenterdatacre pulenricextraction datadenver courtshackingmitm_attacksinjusticetrackingaiee fcff d5domainaustraliafiles ipscript scriptset cookiecookierelated pulseslearnck idname tacticsinformativeadversariescommanddefense evasionspawnsjavascriptascii textpattern matchmitre attnullrefreshspanhybridgenerallocalpathclickstringserrortoolstitlelookverifyrestartaustralia asnas9714 vocusbodycertificatepresent mayjapan unknowna domainsvaluecontent typelocation japanshibuyajapan asnas2497 internetdns resolutionsdomains topunited statesipv4targetingtsara brashearsstate coloradocriticalpornhubtulachsabeypoleassfoundrypalantirpegasusstatequasishhhdenverdougcojeffrey reimerreimer gropeschristopher ahmannworkers compensationcommerce industryaigindustry commerceconfluence
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SLF:MSIL/PSTAnomaly.A Win.Trojan.Pushdo-20 TrojanDownloader:Win32/Cutwail.BS TrojanDownloader:Win32/Cutwail.BV World Media CVE-2022-26134
Indicators of Compromise (131 / 5051 total)
All FileHash-SHA256 hostname domain URL FileHash-MD5 FileHash-SHA1 CVE email SSLCertFingerprint
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 8f86676bbba888f4c3c4c7e3b4fdb4b2 MD5 of 12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64 2026-04-27
FileHash-MD5 4bcfe9f8db04948cddb5e31fe6a7f984 MD5 of bee0439fcf31de76d6e2d7fd377a24a34ac8763d5bf4114da5e1663009e24228 2026-04-27
FileHash-MD5 d586601d415e05a77c71d9f3b6b1cac7 MD5 of b7e002005b4464d7d74d6c4d37f9fd25b6309b6504de57ab85b5fccb05427089 2026-04-27
FileHash-MD5 02ed95e92ef302b9c28ed8d735efe738 MD5 of 17c8115b3e609c5b1d13f7eb9e49f482ff515d484eb0948c8226ebe0fd78276c 2026-04-27
FileHash-MD5 08d5b6dd21ebfe79b2887283fd09ec87 MD5 of 9c59cf262983b5a35efefdba0e408c229ed8d28a7eea8fa43633370535475c27 2026-04-27
FileHash-MD5 0a593f848a98f87090d98d7840511fb0 MD5 of 81a96e3e9bf5bd35e9b82ae141b4b618f0ef3ca824aebc1cf1e33327f407ac79 2026-04-27
FileHash-MD5 27562734bd0eff9434a8aa8bed4ca874 2026-04-27
FileHash-MD5 28caeadef67de2449436ba5f953d7bfa 2026-04-27
FileHash-MD5 2cdd56a1b57af8a63750b8963e263c08 MD5 of 402a4ed3b5bfdc03a398705c69e696cf48d3222ed3f9ff10c5eb93ab58439215 2026-04-27
FileHash-MD5 2ce7cfa7ed38cbf22ffcda014850102f MD5 of 54bda6cf1cffa0cb553c2565653e73d79b0d7c665b70bf2f03f12ec5b635284f 2026-04-27
FileHash-MD5 341d067ed6356042cc64dc36dad4f100 2026-04-27
FileHash-MD5 76fbf6295dad37868193bec9cd88fdf3 2026-04-27
FileHash-MD5 971822c92c9279ea7a5185d9cb6c4481 2026-04-27
FileHash-MD5 9cc492d942e2dcdfdda8f5245ce5b649 MD5 of 6cf3f690eaa26fc7e2e7d7abaa17add361fdc04432ba9d8cdada4fde699cd287 2026-04-27
FileHash-MD5 a0e1ff72d64f3c45281c26cf91c198cf MD5 of a5e3ded4dff907d728cdb22d85f0ebfe65895189bc1b13983d6687d46476efe0 2026-04-27
FileHash-MD5 aacfa18a49f23665ff32b6d3060e9f8e MD5 of c254b4fae14e0fed6289de459f579ace0bdba6d5254fc8b314eceeeba954dbec 2026-04-27
FileHash-MD5 d33d1bcab0e84efe5353eda2047f618a 2026-04-27
FileHash-MD5 dbf2aac9794df26bb34dcfe0dc2ca2a0 2026-04-27
FileHash-MD5 e65889ccf07e7f6cce7e86dba8c1e824 2026-04-27
FileHash-MD5 eadbbaa5864b60ec593c9e95564bc52c 2026-04-27
FileHash-MD5 ec685a0ee4b633f7b97ed5a20531e72a MD5 of 80d599121ff5fbf23e9513645f85dc1537305ad8f018915976b2aa3dc8cee907 2026-04-27
FileHash-MD5 f00a27da206cf96c978eb2c2ea01c034 MD5 of 5d1e8f9491b1ffc50842f01bbb0840614100ade16bbe3480dc9a3b502af28193 2026-04-27
FileHash-MD5 f34d5f2d4577ed6d9ceec516c1f5a744 2026-04-27
FileHash-MD5 f573ea1fe9111ec046c0e7b7e4ee8090 2026-04-27
FileHash-MD5 0ad4ee92a17129f2b8b71675c0d151bc 2026-04-27
FileHash-MD5 2b4bb0f01051e81a72c7773bfb7912c3 2026-04-27
FileHash-MD5 ba3bb0388283a428324b62a629eeb9ca 2026-04-27
FileHash-MD5 d794728bb9a4109384bef454b41dbbba 2026-04-27
FileHash-MD5 f66bd6c5ca8e75c99c0fc96364aafcd6 2026-04-27
FileHash-MD5 20f0110ed5e4e0d5384a496e4880139b 2026-04-27
FileHash-MD5 26f971d87ca00e23bd2d064524aef838 2026-04-27
FileHash-MD5 5565250fcc163aa3a79f0b746416ce69 2026-04-27
FileHash-MD5 5a5dc2f9e9c66b74d361d490c1f4357b 2026-04-27
FileHash-MD5 9234071287e637f85d721463c488704c 2026-04-27
FileHash-MD5 c1b5664bd6dfce36ad6cc474277eee31 2026-04-27
FileHash-MD5 d65ec06f21c379c87040b83cc1abac6b 2026-04-27
FileHash-MD5 e4a1c9189d2b01f018b953e46c80d120 2026-04-27
FileHash-MD5 f4fe1cb77e758e1ba56b8a8ec20417c5 2026-04-27
FileHash-MD5 af016325a035a51384e60676b571056f 2026-04-27
FileHash-MD5 08dab26d6c1f74d95ae4b7375c949807 MD5 of af393c97914697f367023c83e8544521b8d621b3add2538166f44125251c0918 2026-04-27
FileHash-MD5 0faf7d9daad9eaf6481b7bb69bdb26b7 MD5 of 07d923e8f7f69e6f36e2226723e8c1abed527b999942669a8eff8c50a0be65f6 2026-04-27
FileHash-MD5 0fc8708407d62708a5adf8f84c4038f1 MD5 of 1642a0e331de8bda30ea7ff6dbb80074f109b98dfaa9417eda8d770aff334dac 2026-04-27
FileHash-MD5 70bc8f4b72a86921468bf8e8441dce51 MD5 of 66687aadf862bd776c8fc18b8e9f8e20089714856ee233b3902a591d0d5f2925 2026-04-27
FileHash-MD5 72316740ce7e73ac706879ca55940ac3 MD5 of 546900b6f0800671d46058758a0fb3c497887a39be84778a984f35bbd231393b 2026-04-27
FileHash-MD5 9f09cf7bb38a28604b82294714b5aff8 MD5 of d2d8ccd68849e94ea6b84f6835d0fe98ffa5c11e74a1138529e3c0b8d8edfe60 2026-04-27
FileHash-MD5 a2cda5a9f871c52db3d9147f6ac9ca0d MD5 of a1e983d9b4729f4a7c928892dcdc1ac32a3342a49eaf98d5a81e5e13903dd25c 2026-04-27
FileHash-MD5 aca80bf62c3726ec21e5584a49453727 MD5 of 2997b002c00b1865b5b0345619219d5be41eecbaa1edd06939c10f9aef49b077 2026-04-27
FileHash-MD5 bf619eac0cdf3f68d496ea9344137e8b MD5 of 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 2026-04-27
FileHash-MD5 d32a8448539d4a442d9f049bb2deccea MD5 of 104915c36c8fad3a35a79dbb899c27e51f2b739c27dd62e5717098c78ee16aea 2026-04-27
FileHash-MD5 d59e0d372ea5fd8c1f4de744376a6af4 MD5 of b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b 2026-04-27
FileHash-MD5 60cd813e3334d06ef67f189f91da4efb MD5 of 9c270f1394cdb4387eee8669b11c7b5a05b7be6740513b0f92f04732e7c73f91 2026-04-27
FileHash-MD5 e984a168f8e638d43edfb36848b5704b MD5 of c7a0965ecd6d4e5648cc4d62f9870325dc45d3f09eaa4e94fdc9df31dfc866c6 2026-04-27
FileHash-MD5 9698f46495ce9401c8bcaf9a2afe1598 2026-04-27
FileHash-MD5 b47266fef17ad4b2e4ca6ee1d06c39a7 2026-04-27
FileHash-MD5 1db030b3bc1f272415e9c7a7fb0fd516 MD5 of 9f85450f9362581f1c93079e9e2dcf90411f74f5d247bccdfb952e301fb05a6a 2026-04-27
FileHash-MD5 269cb38ce44a9715f158dcd48dde6e63 MD5 of c44f2ce9517d4112b9e502b486e2d16aec76d8ac0d4032555b7d851a43bfa5bb 2026-04-27
FileHash-MD5 37f8d313da0b370f58707008fe6868f2 MD5 of eaae595de62dd4d15cfd626dedf115b95ccb258248d55ec8d84e803694bd889a 2026-04-27
FileHash-MD5 49aebf8cbd62d92ac215b2923fb1b9f5 2026-04-27
FileHash-MD5 53c9458013619ea1b4112ba472358ce9 MD5 of a272e3257e997536019059282a816711800cf0bb8766aea75f4ed21390977787 2026-04-27
FileHash-MD5 58f6918fde7202e07010ceb4c68bfc7c MD5 of 6912b0e08e0c11ff91f50231e1d24f258408a2aab3ce9a0c180396f648710e51 2026-04-27
FileHash-MD5 77ec63bda74bd0d0e0426dc8f8008506 2026-04-27
FileHash-MD5 8b744b4727c4bb12d5c366952454fbb1 MD5 of 2ea9a2b3728d5a6917b040480047e418a7c543bad44752ec00958280099fca39 2026-04-27
FileHash-MD5 9cc58992837ed0ed0260c0727355a558 2026-04-27
FileHash-MD5 a03b6516b95698b6f828c1fec18527d0 2026-04-27
FileHash-MD5 a99934c9d833606fd3a303948fdb52c6 2026-04-27
FileHash-MD5 cde3384baf175d94cb59e91bca0b9bfa MD5 of b96b6b6bbf75d48ab68d1d5b3e5f90fc970207679177bb44100c471dff0a4dd4 2026-04-27
FileHash-MD5 d337928f9097e55a05f3e504e4670bcb MD5 of 16ab3e25ae505aefb606d6ed011928561c6faa2b74a99499d9d1f40d6572cfff 2026-04-27
FileHash-MD5 db95a4cb23548a635a1dfebcee9991cb 2026-04-27
FileHash-MD5 e5276dffbee7cd1db73ab08e545f4ee0 MD5 of cf1fa7c33b6ccc18cebc6867fa6b7019bea9d7192a6bb9c10756c757413159f0 2026-04-27
FileHash-MD5 fa65bc7f6473a7c2da9e0c512934776e MD5 of 990782fe210dd08e5ae875d70240b4aff42bed541466aca32e302faa257ef1ab 2026-04-27
FileHash-MD5 005eb563738fb1ed6cc2028ed1b1647f MD5 of 1f8eba9c5596fb5f423b08f35ba698e1693cd53adcfa4100210fda52a10c16ef 2026-04-27
FileHash-MD5 2dc1760ffefc9de3ba49a8373704aacf MD5 of 80ff5df7fc7f5fa0031611b02c75c71e3a84217eadb4eb9cfd2e62a88697aa92 2026-04-27
FileHash-MD5 66aca36e03640fc15e96709f32ee358f MD5 of 4014bd802f609b151e096f5550cb6027cd50383181a3f90f57247c63289817d7 2026-04-27
FileHash-MD5 1bb37545a47ea7c9719cf01d18ec5f04 2026-04-27
FileHash-MD5 da1f5411a665b0d7664572fdd2ec9170 MD5 of a8a33f99d0c761d07c1271a5f8f29e73590cd69f32b93e00f87c549658c7e63e 2026-04-27
FileHash-MD5 0657dda51c0c9e3cf07d7c7fc5f4f3f2 2026-04-27
FileHash-MD5 070e0202839d9d67350cd2613e78e416 2026-04-27
FileHash-MD5 2d9dd48095f1f3ab6e35b8749625d598 2026-04-27
FileHash-MD5 2da82207a37497ad71350337e367da96 2026-04-27
FileHash-MD5 3993f1bd4cd8a7e27fa646f1b8fe270b 2026-04-27
FileHash-MD5 39ddd708f854bd9a1969785d86111268 2026-04-27
FileHash-MD5 55540a230bdab55187a841cfe1aa1545 2026-04-27
FileHash-MD5 57c8edb95df3f0ad4ee2dc2b8cfd4157 2026-04-27
FileHash-MD5 58c3ec8f3029504e671c21a3897360bc 2026-04-27
FileHash-MD5 7addd1fe9a4aa5b09bb8aec658889257 2026-04-27
FileHash-MD5 c1ed44b2f8b3fdb187e28a55ae2d96ec 2026-04-27
FileHash-MD5 cbdb22504682b9428b260cc1fbce93c0 2026-04-27
FileHash-MD5 daba17f5e36cbe65640dd2fe24f104e7 2026-04-27
FileHash-MD5 dbb0c928c8ddd131313fbce1686e68e8 2026-04-27
FileHash-MD5 0256a0990cfa8c7f7b0cc4ff012343bf MD5 of 53147050a3f5fd26d55c175c3f9191898fee2c72af8f44de2f6e8681ba465096 2026-04-27
FileHash-MD5 32d952278e749a7f181c303c25598154 MD5 of 527c8f5cda8b8bc200c2f1d93aedeeea7e89476524e6b98c3f1c42d30395e7bf 2026-04-27
FileHash-MD5 6cf6890b86ed9f0fe029f2d9d65501ae MD5 of 470c1ca449f2d88631f28eb42a24fd8fe50be486 2026-04-27
FileHash-MD5 8aa48b00dd80d2085cbbd81726a688be 2026-04-27
FileHash-MD5 b914d88f6979a4926eeded014a61a088 MD5 of 6dda84882db1388ee5eba67e3047badd9bb49af6afdc07ad4de5708c382ce893 2026-04-27
FileHash-MD5 006087991c2f2fd96eff7d1ee943fece 2026-04-27
FileHash-MD5 03eb2df2aaf347eea0aaf72792e27d6a 2026-04-27
FileHash-MD5 06db9daf4cb4a1a0b4119de45a806c42 2026-04-27
FileHash-MD5 0acacf1a99749dca7820eeee8a3c3cd2 2026-04-27
FileHash-MD5 2c45d8445a896f8b40a6e4fe7355b869 2026-04-27
FileHash-MD5 30b22d78583dc5f0af20ad63fc72a34a 2026-04-27
FileHash-MD5 32a6f6947de069cd2c89e1dc7c496881 2026-04-27
FileHash-MD5 3f57b781cb3ef114dd0b665151571b7b 2026-04-27
FileHash-MD5 4ac3a6c49a2650b2a8ce709b59c91a40 2026-04-27
FileHash-MD5 52b76a4eefb0f23ff1e8b9bee906ffc3 2026-04-27
FileHash-MD5 5811e4856644cd00bf43c18bcde730e6 2026-04-27
FileHash-MD5 5a34cb996293fde2cb7a4ac89587393a 2026-04-27
FileHash-MD5 5ddc64a53c90f23df0e6462be83931ea 2026-04-27
FileHash-MD5 5f73e0de284de5c474ed09557c9f1554 2026-04-27
FileHash-MD5 6188befef10dd799c12c766cfb62453c 2026-04-27
FileHash-MD5 669b92f015a27baf2ec71a2551390600 MD5 of 76d5f7d229fbde4a974bea3e2bcb7249ead8903d 2026-04-27
FileHash-MD5 6a90876272ccb475eb00f5d5fadfc2d3 2026-04-27
FileHash-MD5 6b26ecfa58e37d4b5ec861fcdd3f04fa 2026-04-27
FileHash-MD5 73c70b34b5f8f158d38a94b9d7766515 2026-04-27
FileHash-MD5 7a3471b439a3c4e42d2012f767dc4129 2026-04-27
FileHash-MD5 812ce7ad9e4f5d1f249f956dd33137d6 2026-04-27
FileHash-MD5 82486d1f8c9e749714670aa5e61a5030 2026-04-27
FileHash-MD5 9618cd4f62a5c104eacd1b4e6f24170e 2026-04-27
FileHash-MD5 9ea7f4b011ca8632e329f7972eb44ccb 2026-04-27
FileHash-MD5 be95f1d5a3939ac5e146585c65a08758 2026-04-27
FileHash-MD5 cdf81e591d9cbfb47a7f97a2bcdb70b9 MD5 of 8f12010dfaacdecad77b70a3e781c707cf328496 2026-04-27
FileHash-MD5 cf1bb6f3f3ef371dd11853b49e5305b9 2026-04-27
FileHash-MD5 cf40aece34491b4f733d0941b71eaa03 2026-04-27
FileHash-MD5 d24e8271357fc37a96e317eea95538d3 2026-04-27
FileHash-MD5 d732a099469635ba3b7f8028d14b90f6 2026-04-27
FileHash-MD5 edda49ec8f0a3dc4c9e37457ea2685e8 2026-04-27
FileHash-MD5 fc06c3351a79aee4aa5da07cc814b548 2026-04-27
FileHash-MD5 fd3b7ce8517a2056eec8723a1bbcf2cc 2026-04-27
FileHash-MD5 a0ee3afe38da6793b0d3acab57b405c3 MD5 of 77f4298fe1c31b0f7ce6ba6de1c6fc327dd86299d47599a4e6f0175041a45832 2026-04-27
FileHash-MD5 0a7cdea35519e7c54c053eb91ba57566 2026-04-27
FileHash-MD5 18d583e9fc4c950e4731775d55e5c94e 2026-04-27
FileHash-MD5 b50f65c58c0bcffae6e93b0b0a374da6 MD5 of 239c8e3378426fbba3d2215692e97ef6d98a76032ab0a2ab4b58bce1414328b3 2026-04-27
References (33)
↗ [DR] Wifi ID Login v1.3 [03 April 2014].exe ↗ 7d10881f146e0d4659948a3555b1eee33950647a3c830978d26f2c8e88d2a90a ↗ bell.ca ↗ indonesiawifi.net • http://welcome.indonesiawifi.net/wifi.id/speedy/?switch_url=http ↗ https://welcome.indonesiawifi.net/wifi.id/flexizone ↗ SLF:MSIL/PSTAnomaly.A SHA1 826d75e406808e3f002cb2b6da09003f78d612a1 [winPEAS.exe] SQLite.Interop.pdb ↗ A target pursued post criminal assault on Pinnacol Assuranve insured premises ↗ https://tms.lingyiitech.com/ELSServer_LYZZ/ • https://oa.lingyiitech.com/login.jsp ↗ IDS Detections: Backdoor.Win32.Pushdo.s Checkin Observed DNS Query to .biz TLD ↗ IDS Detections: HTTP Request to a *.tw domain 403 Forbiddenau ... ↗ Yara Detections: PWSWin32Kegotip , VirusWin32Gogo , VirusWin32Hala , VirusWin32Wholdor ↗ Alerts: behavior_upatre multiple_useragents persistence_autorun network_icmp dead_connect ↗ Alerts:static_pe_anomaly suricata_alert antisandbox_sleep dynamic_function_loading ↗ Alerts: http_request network_cnc_http network_http packer_entropy injection_rwx ↗ Alerts: antidebug_setunhandledexceptionfilter antivm_network_adapters ↗ IP’s Contacted: 143.204.237.45 58.138.175.188 65.38.128.10 147.21.128.26 78.41.204.31 132.148.77.44 ↗ IP’s Contacted: 185.104.29.148 92.122.107.204 139.76.134.15 184.150.211.195 ↗ Domains Contacted: 0handicap.at accountingtechs.biz 4dbenelux.be accountant.com knology.net ↗ Domains Contacted: badactor.us revasal.com yahoo.se excite.fr primus.com.au ↗ Backdoor.Win32.Pushdo.s Checkin ↗ https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian ‘nonsense Denver County Courts) ↗ Name Servers PDNS1.ULTRADNS.NET Org ↗ World Media Group, LLC Address 90 lrojanbownloader.vns. Washington Valley Rd., # ↗ https://otx.alienvault.com/indicator/cve/CVE-2022-26134 ↗ Phishing: http://gravityboard.com/?ptrxcz_quy147AEHKNQUXadgkorvy158BFILO ↗ Created Pulses: NSO Group [Unnamed group] Unnamed group pi, pdfkit.net State of Colorado ↗ CVE-2022-26134 Base Severity: Critical | Targeted | NSO Pegasus Relationships suspected ↗ https://www.mirvish.com/shows/come-from-away&geo=ca&merchantid=407759&useragent=Mozilla/5.0 (Linux; Android 13; Pixel 4a (5G) Build/TQ2A.230505.002; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/112.0.5615.136 Mobile Safari/537.36 GoogleApp/14.16.27.29.arm64 AppEngine-Google; (+ No Expiration ↗ Apple Cons: https://stetsed.xyz/apple • https://www.collierhonorflight.org/apple-touch-icon.png ↗ nr-data.net • https://www.sandoll.co.kr/AppleSDGothicNeo • aka.ms ↗ CVE-2022-26134 • CVSS V3 Severity ATTACK COMPLEXITY: LOW ATTACK VECTOR: NETWORK AVAILABILITY ↗ IMPACT: HIGH BASE SCORE: 9.8 BASE SEVERITY: CRITICAL CONFIDENTIALITY IMPACT: HIGH INTEGRITY IMPACT: HIGH ↗ CVE-2022-26134 • PRIVILEGES REQUIRED: NONE