PULSE NAME
2012: Malware Analysis Report
WHITE kikinumpav 2026-05-01 Modified: 2026-05-01
2918
IOCs
HIGH VOLUME
Indicators of Compromise (84 / 2918 total)
All email IPv4 URL domain hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256 CVE IPv6
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 6d07cf72201234a07ab57fb3fc00b9e5a0b3678e 2026-05-01
FileHash-SHA1 62121738530d17292a75d17421bcd76a4051cad8 2026-05-01
FileHash-SHA1 4fbddb44adf4698e0a828ba6bbf092715193be00 SHA1 of df464de7a6eb04feb95504d74f7505da 2026-05-01
FileHash-SHA1 fb6f092624d48fe9a496c50f615b424b27cf3515 2026-05-01
FileHash-SHA1 c1af1fa6937097762824d0db039777ff35577727 2026-05-01
FileHash-SHA1 023e6c7730445db2b4c777b5d9b612e902dc7f72 2026-05-01
FileHash-SHA1 43ea33bedadc9bfc92c570b316b78b6fd9787f09 2026-05-01
FileHash-SHA1 44561e474bda129379d87750f49fd57a5d378f91 2026-05-01
FileHash-SHA1 f46c445f912c6d1224e22f9e6a76020d594888b9 2026-05-01
FileHash-SHA1 ffadbc944a2976982e1daf0b715478e6062c9488 2026-05-01
FileHash-SHA1 764b4f0202097f2b41a2821d30a7424490bf3a42 2026-05-01
FileHash-SHA1 c1c0cc056d31222d3735e6801acba763ac024c5b 2026-05-01
FileHash-SHA1 0400f9bd7ed0beb42ae42ab76e00b2e68b3c1502 SHA1 of f45963376918ed7dc2b96b16af976966 2026-05-01
FileHash-SHA1 4a4bf11f2f5c753810069302f1ff05d95a625323 SHA1 of 9c072edfb9afa88aa7a379d73b65f82d 2026-05-01
FileHash-SHA1 57ab11a2b8d3d692cbfb6b7601e1b32c3e6076c6 SHA1 of 3702360d1192736020b2a38c5e69263a 2026-05-01
FileHash-SHA1 7562cb609733b4b777bf505b1d9456ca93305937 SHA1 of 89057fc8fedc7da1f300dd7b2cf53583 2026-05-01
FileHash-SHA1 b14487e523ace978fd64860de41b5c2276a50698 SHA1 of 046bcf4ea8297cdf8007824a6e061b63 2026-05-01
FileHash-SHA1 bacb332e0f6c036994ffff17a189b62d5231eb58 SHA1 of 81b2889bab87ab25a1e1663f10cf7e9e 2026-05-01
FileHash-SHA1 502920a97e01c2d022ac401601a311818f336542 2026-05-01
FileHash-SHA1 7c0dc6a8f4d2d762a07a523f19b7acd2258f7ecc 2026-05-01
FileHash-SHA1 0dde72f98a5d0fd673cd6e6935979f2eed6fb624 2026-05-01
FileHash-SHA1 209cd7cdf5e9feaac88c80d19e40f56c25278fcf 2026-05-01
FileHash-SHA1 849bfe083318883d21a22d3c0e60c3ca299eb207 2026-05-01
FileHash-SHA1 782312db766a42337af30093a2fd358eeed97f53 2026-05-01
FileHash-SHA1 b70505e0e8607b94f1f8437f8298d907168d37d5 2026-05-01
FileHash-SHA1 1984d250e62af2f9b3c7099abfe620a8430e043e 2026-05-01
FileHash-SHA1 af9e61177921e81e3f91760a3c7c08020d7fb7ce 2026-05-01
FileHash-SHA1 b7462e83cd81fcbee7b799e230bed19331c9d516 2026-05-01
FileHash-SHA1 5996d02c142588b6c1ed850e461845458bd94d17 2026-05-01
FileHash-SHA1 c36f0943484ce8f8aba2d649aae2ad1243947c4e 2026-05-01
FileHash-SHA1 c520e9099bfc695b54662bdb7e8fa5b2800a72e9 2026-05-01
FileHash-SHA1 465ca6b7e883a7d145ddf6d59e3ef1c0eec279e5 2026-05-01
FileHash-SHA1 7fa7c4af13ad1bcf12b180a5a9cf24613485608c 2026-05-01
FileHash-SHA1 82ad537a7acb18702a02b6dd2c6d12eaac0b3656 2026-05-01
FileHash-SHA1 ee6c14f26962447a30823f9f8d20a53d29322617 2026-05-01
FileHash-SHA1 2d39b6345ac62e950a9ae8a1f1daee1e6f38d9c0 2026-05-01
FileHash-SHA1 791fe17877d9549464a9029cd772a28f77dcbe89 2026-05-01
FileHash-SHA1 2ccb789d57d3ce3dd929307eb78878e6e5c61ccf 2026-05-01
FileHash-SHA1 5050b57e01bb2aa9730f826f36ad4d41477d8bd9 2026-05-01
FileHash-SHA1 d01f76f5467c86bfa266c429e1315e7aad821f93 2026-05-01
FileHash-SHA1 17db1bbaa1bf1b920e47b28c3050cbff83ab16de 2026-05-01
FileHash-SHA1 33395e02036526ef7c3ab05afb137c7af2bcd6df 2026-05-01
FileHash-SHA1 56104a626101126eed10e65171a26e25b6e50712 2026-05-01
FileHash-SHA1 5842f0d4fe3f177f2bb06a2e5878da55f7d814c7 2026-05-01
FileHash-SHA1 6d21fc25b9da49d746b2b7609a5efaed4d332e6a 2026-05-01
FileHash-SHA1 865cf7a7ff3dde0828e7764751d76c8df6291506 2026-05-01
FileHash-SHA1 ed6b36ae9d275e9f988e7ed0e19e92ecdf87621c SHA1 of 5f84282c7ee466e777665ef72fa258b5 2026-05-01
FileHash-SHA1 0b9d01727aac2f858d5f2f09e79737c307f20ae6 SHA1 of 0144f8d76662fc382b8eb094eb347e4b 2026-05-01
FileHash-SHA1 18e65e103a783495b2830e1ec1793eed84d3e437 SHA1 of 83976d6937ebf841999f10bee38ab252 2026-05-01
FileHash-SHA1 1b7ac10d3c11eafdd13a81c4a12d86980c3279b8 SHA1 of 6680e19b115c88416b13b5985bf2c32d 2026-05-01
FileHash-SHA1 1e07cab4c65ca3437418154b4a869647c25f1749 SHA1 of fb11225f453365af4958f98bde2ce918 2026-05-01
FileHash-SHA1 1e3b2233edcaddbd4ad36e66b95180060ba1c888 SHA1 of 47bc44ccd673760918c99856a053aca0 2026-05-01
FileHash-SHA1 1ea1f40b85e72d093e4e7a869a7f3bf1f8d88fd5 SHA1 of 9fe79a8d9901cf773d272b0578c818c7 2026-05-01
FileHash-SHA1 204c7fae8709b13ece3e868defe73e66bce38aa4 SHA1 of 5c920ea7042f820f46ca8bdeb9a17519 2026-05-01
FileHash-SHA1 286552cca75c87c8d62cb58e07496cea4c1d2183 SHA1 of 0a5446da47609868101c773e928b36e4 2026-05-01
FileHash-SHA1 2cf14a67b4c4f966561c78696b8e486974c2dc73 SHA1 of f362f47eb844f889bafd5a0e92c7cdf0 2026-05-01
FileHash-SHA1 3798adaa9686d88f57a4841460622a8d087f8e09 SHA1 of 52856c1a0c63509bf6c00ef1e9fca03c 2026-05-01
FileHash-SHA1 3de7f4ca846436cb9246d2ec9fb8ec7edff633cf SHA1 of a3a1ea2c99d40620fc8dee0222228f24 2026-05-01
FileHash-SHA1 4008caac047f7e5db9d8333f5bf47b6ecb886025 SHA1 of a1a977867a889be58767f3224806aef3 2026-05-01
FileHash-SHA1 42640360c12a72e36fd771a01b486a44f36cf2f0 SHA1 of 3270d18157131f216468cf7ce53ee8d1 2026-05-01
FileHash-SHA1 4e078e0e1e6499c111819c7311c4a8755386a461 SHA1 of 89ffcc729bf4b89a298b0dd317228646 2026-05-01
FileHash-SHA1 4e5ad494f7240691e14bb3a9a4a39e0f6489169a SHA1 of 9133dcec65eb468ce226e1fd8accaf4e 2026-05-01
FileHash-SHA1 525bbc2f0887d5a105f08c931d1d0cc78f669372 SHA1 of e691dc42a002e9f48f69cd33b70d8a15 2026-05-01
FileHash-SHA1 6f52c7a4ffa8f5dee86b8d7c77f730d4f38c0439 SHA1 of ef80d287bd10af3b1cab06d01795ae1a 2026-05-01
FileHash-SHA1 7654bd46e606f4bba773708309dd53cbf0d09d8c SHA1 of a83fc05a18e18ba19e93a75ffa6ebd50 2026-05-01
FileHash-SHA1 798bf4988b344b29a9c8095025dd6015cf5de658 SHA1 of e61b128e97a39fe869cf89be571fe021 2026-05-01
FileHash-SHA1 821ac8971c6be813d2adb3e9e5ca3e11800c1292 SHA1 of 7547a4e39ac61eae20c79fa3834d8e2a 2026-05-01
FileHash-SHA1 86b9ca962ecebf7d858fe2f1a518de92076abe2a SHA1 of e21c8e1c3e79d669f13f771dbbe0eb77 2026-05-01
FileHash-SHA1 9abbd6d68b4f8786006e5e5d01448fe0b23b4a8d SHA1 of 9a09e5acd4050a68ade420fcc79c6c66 2026-05-01
FileHash-SHA1 bb308ec7401b63f88929403c252e40eeeccf611d SHA1 of 66fc71e3f35b3ef21cf524c3be92708c 2026-05-01
FileHash-SHA1 bd71907c74a548c6da809b7130ab69a404431ecd SHA1 of 90bf1a608159df6c4f11f6366cecb998 2026-05-01
FileHash-SHA1 bfad34cfd99ef25e5b9f5f77b5baf97f42f21758 SHA1 of 45d07b1a0a6cea3035d448e384b59252 2026-05-01
FileHash-SHA1 d9afde7a09564a8cb66e4637e6b0704e661954fc SHA1 of 49b7bc9ac3800caa49bca0a4b3350dbd 2026-05-01
FileHash-SHA1 dd72847f99e88a46236456bb49999eba2110d3f5 SHA1 of d8ca81ee8327d8314121d1560800674c 2026-05-01
FileHash-SHA1 e3342ad1d97af0c8d8e00e7f2e30b05fe0e2e8e0 SHA1 of 06572d93d87a8d0fb7e070be79692c87 2026-05-01
FileHash-SHA1 e9c7b38ac8d5e2535ccd04c77c5a1cf68cabb778 SHA1 of eebfa7677dedd10edf4aca985f16284c 2026-05-01
FileHash-SHA1 f4702118952bfc1f5dbd4430b9301995ff70ddb4 SHA1 of 84356ed469c95c1418209bd929640622 2026-05-01
FileHash-SHA1 f60c8346fcd2cdfa7f8168331b8304a6a4511eb6 SHA1 of 93cf1393241577797b36d707d4255faa 2026-05-01
FileHash-SHA1 f7fbbda6c549cbb5b5a1bb944a315e07c0a1e93f SHA1 of 71313fcf3d825ba40375cf62f4777e10 2026-05-01
FileHash-SHA1 f8215cd420c5617868639024a50945de04d33202 SHA1 of 50ecc77c6c831bcd7e0534353f61c479 2026-05-01
FileHash-SHA1 fd28b6fc289b73599da98f4e357031b13a4efcb4 SHA1 of 09c44fcceb51f9affdb63b0d8f9e4b31 2026-05-01
FileHash-SHA1 ff0e4d623ce71adfba08e74273711daff020d348 SHA1 of cff8e4eb16d010bcc33ad19eb807bd27 2026-05-01
FileHash-SHA1 ff42be2b184077950e7298400295803e2d5e1baa SHA1 of 39762af48276967a54372dca1f89936c 2026-05-01
FileHash-SHA1 5ea6ae50063da8354e8500d02d0621f643827346 2026-05-01
References (119)
↗ 2012-01-04 - SpyEye Malware Borrows Zeus Trick to Mask Fraud.pdf ↗ 2012-01-08 - Cold$eal- 'Situation is under control'.pdf ↗ 2012-01-06 - Cracking Cold$eal 5.4.1 FWB++.pdf ↗ 2012-01-06 - Cracking ColdSeal 5.4.1 FWB.pdf ↗ 2012-02-15 - Merchant of Fraud Returns- Shylock Polymorphic Financial Malware Infections on the Rise.pdf ↗ 2012-02-01 - TDL4 - Purple Haze (Pihar) Variant - sample and analysis.pdf ↗ 2012-01-12 - Blackhole Ramnit - samples and analysis.pdf ↗ 2012-03-16 - OSX-Imuler updated- still a threat on Mac OS X.pdf ↗ 2012-03-26 - LUCKYCAT REDUX Inside an APT Campaign with Multiple Targets in India and Japan.pdf ↗ 2012-03-06 - Virus Ukash Gendarmerie Absence twexx32.dll.pdf ↗ 2012-04-05 - Darkshell DDOS Botnet Evolves With Variants.pdf ↗ 2012-04-16 - Detailed Analysis Of Sykipot (Smartcard Proxy Variant).pdf ↗ 2012-04-10 - OSX-FlashbackO sample and some domains.pdf ↗ 2012-04-05 - China Hacked South Korea Over Missile Defense, U.S. Firm Says.pdf ↗ 2012-04-10 - OSX-Flashback.O sample + some domains.pdf ↗ 2012-04-12 - OSX-Flashback.K sample + Mac OS malware study set (30+ older samples).pdf ↗ 2012-04-12 - OSX-Flashback.K sample and Mac OS malware study set (over 30 older samples).pdf ↗ 2012-04-23 - BKDR_CYSXL.A.pdf ↗ 2012-04-18 - DarkMegi rootkit - sample (distributed via Blackhole).pdf ↗ 2012-05-31 - Flamer- A Recipe for Bluetoothache.pdf ↗ 2012-06-06 - Tinba - Zusy - tiny banker trojan.pdf ↗ 2012-06-04 - Small banking Trojan poses major risk.pdf ↗ 2012-05-28 - The Flame- Questions and Answers.pdf ↗ 2012-06-05 - Smartcard vulnerabilities in modern banking malware.pdf ↗ 2012-06-09 - You dirty RAT! Part 1- DarkComet.pdf ↗ 2012-06-21 - BlackShades in Syria.pdf ↗ 2012-06-15 - You Dirty RAT! Part 2 – BlackShades NET.pdf ↗ 2012-07-02 - Sykipot is back.pdf ↗ 2012-06-24 - Medre.A - AutoCAD worm samples.pdf ↗ 2012-06-21 - RAT samples from Syrian Targeted attacks - Blackshades RAT, XTreme RAT, Dark Comet RAT used by Syrian Electronic Army.pdf ↗ 2012-07-17 - Kaspersky Lab and Seculert Announce ‘Madi,’ a Newly Discovered Cyber-Espionage Campaign in the Middle East.pdf ↗ 2012-07-17 - The Madi Attacks- Series of Social Engineering Campaigns.pdf ↗ 2012-07-13 - Rovnix bootkit framework updated.pdf ↗ 2012-07-26 - The Madi Campaign – Part II.pdf ↗ 2012-07-22 - Xtreme RAT analysis.pdf ↗ 2012-08-01 - “RunForestRun”, “gootkit” and random domain name generation.pdf ↗ 2012-07-24 - New Apple Mac Trojan Called OSX-Crisis Discovered.pdf ↗ 2012-07-17 - The Madi Campaign – Part I.pdf ↗ 2012-08-01 - Inside the ICE IX bot, descendent of Zeus.pdf ↗ 2012-08-10 - Gauss samples - Nation-state cyber-surveillance + Banking trojan.pdf ↗ 2012-08-02 - Cridex Analysis using Volatility.pdf ↗ 2012-08-17 - Shamoon or DistTrack.A samples.pdf ↗ 2012-08-20 - Crisis for Windows Sneaks onto Virtual Machines.pdf ↗ 2012-08-16 - Shamoon the Wiper – Copycats at Work.pdf ↗ 2012-08-16 - The Shamoon Attacks.pdf ↗ 2012-08-16 - Inside Upas Kit (1.0.1.1) aka Rombrast C&C - Botnet Control Panel.pdf ↗ 2012-08-22 - The first Trojan in history to steal Linux and Mac OS X passwords.pdf ↗ 2012-08-30 - Troj-Binanen-B.pdf ↗ 2012-09-18 - QassamCyberFighters's Pastebin.pdf ↗ 2012-09-01 - URLZone reloaded- new evolution.pdf ↗ 2012-09-28 - Dissecting 'Operation Ababil' - an OSINT Analysis.pdf ↗ 2012-10-02 - Blackhole Exploit Kit – Rise and Evolution.pdf ↗ 2012-09-06 - The Elderwood Project.pdf ↗ 2012-09-19 - Blog Posts on Nitol.pdf ↗ 2012-08-13 - Syrian Electronic Army.pdf ↗ 2012-10-09 - BKDR_SARHUST.A.pdf ↗ 2012-10-05 - Dark Comet 2- Electric Boogaloo.pdf ↗ 2012-10-12 - New Multiplatform Backdoor Jacksbot Discovered.pdf ↗ 2012-10-09 - SASFIS.pdf ↗ 2012-10-13 - WORM_EMUDBOT.JP.pdf ↗ 2012-10-07 - Cracking New PseudoRandom (runforestrun) Infector.pdf ↗ 2012-11-01 - Tracking the 2012 Sasfis campaign.pdf ↗ 2012-11-16 - Malware Targeting Windows 8 Uses Google Docs.pdf ↗ 2012-11-13 - New variant of Mac Trojan discovered, targeting Tibet.pdf ↗ 2012-11-14 - Group Photos.zip OSX-Revir - OSX-iMuler samples March 2012-November 2012.pdf ↗ 2012-11-16 - Remote Administration Tool for Android devices.pdf ↗ 2012-11-05 - Citadel- a cyber-criminal’s ultimate weapon-.pdf ↗ 2012-10-30 - JACKSBOT Has Some Dirty Tricks up Its Sleeves.pdf ↗ 2012-11-27 - Threat Description- Troj-Ployx-A.pdf ↗ 2012-11-22 - W32.Narilam – Business Database Sabotage.pdf ↗ 2012-12-03 - Compromised library.pdf ↗ 2012-11-25 - Parastoo Hacks IAEA.pdf ↗ 2012-12-03 - New Mac Malware Found on Dalai Lama Related Website.pdf ↗ 2012-11-28 - Shylock’s New Trick- Evading Malware Researchers.pdf ↗ 2012-11-29 - Inside view of Lyposit aka (for its friends) Lucky LOCKER.pdf ↗ 2012-12-06 - Nov 2012 - W32.Narilam Sample.pdf ↗ 2012-12-07 - Aug 2012 Backdoor.Wirenet - OSX and Linux.pdf ↗ 2012-12-05 - The path to infection - Eye glance at the first line of -Russian Underground- - focused on Ransomware.pdf ↗ 2012-12-07 - Aug 2012 W32.Crisis and OSX.Crisis - JAR file Samples - APT.pdf ↗ 2012-12-07 - Nov 2012 - Backdoor.W32.Makadocs Sample.pdf ↗ 2012-12-12 - Analysis of VirTool-WinNT-Exforel.A rootkit.pdf ↗ 2012-12-07 - Nov 2012 Worm Vobfus Samples.pdf ↗ 2012-12-12 - Unpacking Dexter POS -Memory Dump Parsing- Malware.pdf ↗ 2012-12-13 - The Dexter Malware- Getting Your Hands Dirty.pdf ↗ 2012-11-29 - What’s the Fuss with WORM_VOBFUS-.pdf ↗ 2012-12-15 - Disclosure of another 0day malware - Initial Dropper and Downloader (Part 1).pdf ↗ 2012-12-19 - Win32-Spy.Ranbyus modifying Java code in RBS Ukraine systems.pdf ↗ 2012-12-17 - Sample for Sanny - Win32.Daws in CVE-2012-0158 -ACEAN Regional Security Forum- targeting Russian companies.pdf ↗ 2012-12-18 - Malicious Apache module used for content injection- Linux-Chapro.A.pdf ↗ 2012-12-20 - Trojan.Stabuniq Found on Financial Institution Servers.pdf ↗ 2012-12-15 - Disclosure of another 0day malware - Analysis of 2nd Dropper and 3rd Dropper (Part 2).pdf ↗ 2012-12-23 - Dec 2012 Dexter - POS Infostealer samples and information.pdf ↗ 2012-12-24 - Dec 2012 Linux.Chapro - trojan Apache iframer.pdf ↗ 2012-12-27 - Nitol botnet.pdf ↗ 2012-12-21 - Infostealer Dexter Targets Checkout Systems.pdf ↗ 2012-12-24 - Dec. 2012 Trojan.Stabuniq samples - financial infostealer trojan.pdf ↗ 2012-12-29 - Attack and IE 0day Informations Used Against Council on Foreign Relations.pdf ↗ 2012-12-26 - ZeroAccess - Sirefef Rootkit - 5 fresh samples.pdf ↗ Crypto -Dark Comet.pdf ↗ Cyberattack against Israeli and Palestinian targets.pdf ↗ Dark Comet.pdf ↗ IEXPL0RE RAT.pdf ↗ OSX SabPub.pdf ↗ Flamer C & C Server.pdf ↗ Ixeshe.pdf ↗ Shamoon.pdf ↗ Pest Control.pdf ↗ The elderwood project.pdf ↗ The Mirage Campaign.pdf ↗ The Sin Digoo Affair.pdf ↗ Trojan Taidoor.pdf ↗ Wicked Rose & NCPH Hacking Group.pdf ↗ Fin Fisher's Spy Kit.pdf ↗ LuckyCat Redux.pdf ↗ The Madi Infostealers.pdf ↗ The VOHO Campaign.pdf ↗ The taidoor campaign.pdf ↗ The HeartBeat APT Campaign.pdf ↗ Tibet Lurk.pdf