PULSE NAME
CAPE Sandbox- LOTA- Living off the Admin
WHITE msudosos 2026-05-07 Modified: 2026-05-08
2434
IOCs
HIGH VOLUME
The sandbox analysis reveals several high-risk activities that align with modern malware strains. Persistence Mechanisms: The file attempts to modify registry keys and drop executable files in sensitive directories, typical of malware seeking to survive system reboots.Network Communications: It initiates connections to known malicious C2 (Command and Control) infrastructure. This includes resolving DGA (Domain Generation Algorithm) domains and attempting P2P communication.Process Injection: The sample often spawns or injects code into legitimate system processes to evade detection by standard antivirus engines.Data Exfiltration: Observed behavioral signatures include calls to APIs used for harvesting credentials and system metadata, which are then queued for outbound transmission. Network comms 385 HTTP 656 DNS 702 IP 1 JA3. [fcedee2f..] f0r5afo[.exe] 12/28/16 first appearance. 104.31.74.222 Ip I tagged 30 other malcious [exe] in here too. ref file: [e0c]
Indicators of Compromise (85 / 2434 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname CIDR email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 00abefd055f9a9c784ffdeabd1dcdd8fed741436 2026-05-07
FileHash-SHA1 06b25927c42a721631c1efd9431e648fa62e1e39 2026-05-07
FileHash-SHA1 0cb5b9a9711e32f71d7e49a9994248dbcb95d4eb 2026-05-07
FileHash-SHA1 0eb4300ea577104a84b0b86dc450147d97f975a9 2026-05-07
FileHash-SHA1 108fbf794e18ec5347a414e4370cc4506c297ab2 2026-05-07
FileHash-SHA1 1b511abead59c6ce207077c0bf0e0043b1382612 2026-05-07
FileHash-SHA1 21c88997e474d4f8ecf84ab706919737fb20a36f 2026-05-07
FileHash-SHA1 252fc37983af87db6d0e1c5abbf7286cc60d4641 2026-05-07
FileHash-SHA1 27ac9369faf25207bb2627cefaccbe4ef9c319b8 2026-05-07
FileHash-SHA1 2b7dc50918f6471e6adba3ec065649ff221a5950 2026-05-07
FileHash-SHA1 2b8f1b57330dbba2d07a6c51f70ee90ddab9ad8e 2026-05-07
FileHash-SHA1 33e4e80807204c2b6182a3a14b591acd25b5f0db 2026-05-07
FileHash-SHA1 3caf0c37f78f3fedee8f144887fff6237e877c3c 2026-05-07
FileHash-SHA1 40cef3046c916ed7ae557f60e76842828b51de53 2026-05-07
FileHash-SHA1 414a2060b738c635cc7fc243e052615592830c53 2026-05-07
FileHash-SHA1 47beabc922eae80e78783462a79f45c254fde68b 2026-05-07
FileHash-SHA1 4d3196b5f8542ae67e8baf5b981f44a8a9921dee 2026-05-07
FileHash-SHA1 5f28d9c589ee4bf31a11b78c72b8d13f079ddc45 2026-05-07
FileHash-SHA1 696db3af0dffc17e65c6a20d925c5a7bd24dec7e 2026-05-07
FileHash-SHA1 75aa215ce3c1902e93c7c36a34c7f12ca4571911 2026-05-07
FileHash-SHA1 7ca9fcdbd712556013319038cf814389968ab258 2026-05-07
FileHash-SHA1 8b3c5b9b867d4be46d1cb5a01d45d67dc8e94082 2026-05-07
FileHash-SHA1 8cf427fd790c3ad166068de81e57efbb932272d4 2026-05-07
FileHash-SHA1 925a8f8d2c6d04e0665f596aff22d863e8256f3f 2026-05-07
FileHash-SHA1 932bed339aa69212c89375b79304b475490b89a0 2026-05-07
FileHash-SHA1 9660798bcba4b6022ca668852add7696ef311c8d 2026-05-07
FileHash-SHA1 9e99a48a9960b14926bb7f3b02e22da2b0ab7280 2026-05-07
FileHash-SHA1 ad7e1c28b064ef8f6003402014c3d0e3370eb58a 2026-05-07
FileHash-SHA1 b1bc968bd4f49d622aa89a81f2150152a41d829c 2026-05-07
FileHash-SHA1 b5abc4899c888c938d03c1af467bed493b889b7b 2026-05-07
FileHash-SHA1 ba23087767e3c84b4b3c7df5dd7243e09d40a8f1 2026-05-07
FileHash-SHA1 ca7788c32da1e4b7863a4fb57d00b55ddacbc7f9 2026-05-07
FileHash-SHA1 cabd2a79a1076a31f21d253635cb039d4329a5e8 2026-05-07
FileHash-SHA1 cc136695639065fab47074d28c55314c66077e90 2026-05-07
FileHash-SHA1 cdf46b4fb3998929e571c12a193742ef92609396 2026-05-07
FileHash-SHA1 cf42262e00c2b1cb0c6f4f90b1f06265fa1c2a4c 2026-05-07
FileHash-SHA1 d1eb23a46d17d68fd92564c2f1f1601764d8e349 2026-05-07
FileHash-SHA1 d6908965a3bf5c4e29d8295414d635e1894cfce3 2026-05-07
FileHash-SHA1 d6aee31631f7abc56b9de8abeccc4108a626b104 2026-05-07
FileHash-SHA1 d9fe0a65fa00cabf61f5120d373a8135e1461f15 2026-05-07
FileHash-SHA1 df3c24f9bfd666761b268073fe06d1cc8d4f82a4 2026-05-07
FileHash-SHA1 e84990cb9bf8e3ab0bcae8a649cb30fe4dc4d767 2026-05-07
FileHash-SHA1 d9a909bd3c872a2abaa6ce3022c6b918e45050fb 2026-05-07
FileHash-SHA1 00abefd055f9a9c784ffdeabd1dcdd8fed741436 2026-05-07
FileHash-SHA1 06b25927c42a721631c1efd9431e648fa62e1e39 2026-05-07
FileHash-SHA1 0cb5b9a9711e32f71d7e49a9994248dbcb95d4eb 2026-05-07
FileHash-SHA1 0eb4300ea577104a84b0b86dc450147d97f975a9 2026-05-07
FileHash-SHA1 108fbf794e18ec5347a414e4370cc4506c297ab2 2026-05-07
FileHash-SHA1 1b511abead59c6ce207077c0bf0e0043b1382612 2026-05-07
FileHash-SHA1 21c88997e474d4f8ecf84ab706919737fb20a36f 2026-05-07
FileHash-SHA1 252fc37983af87db6d0e1c5abbf7286cc60d4641 2026-05-07
FileHash-SHA1 27ac9369faf25207bb2627cefaccbe4ef9c319b8 2026-05-07
FileHash-SHA1 2b7dc50918f6471e6adba3ec065649ff221a5950 2026-05-07
FileHash-SHA1 2b8f1b57330dbba2d07a6c51f70ee90ddab9ad8e 2026-05-07
FileHash-SHA1 33e4e80807204c2b6182a3a14b591acd25b5f0db 2026-05-07
FileHash-SHA1 3caf0c37f78f3fedee8f144887fff6237e877c3c 2026-05-07
FileHash-SHA1 40cef3046c916ed7ae557f60e76842828b51de53 2026-05-07
FileHash-SHA1 414a2060b738c635cc7fc243e052615592830c53 2026-05-07
FileHash-SHA1 47beabc922eae80e78783462a79f45c254fde68b 2026-05-07
FileHash-SHA1 4d3196b5f8542ae67e8baf5b981f44a8a9921dee 2026-05-07
FileHash-SHA1 5f28d9c589ee4bf31a11b78c72b8d13f079ddc45 2026-05-07
FileHash-SHA1 696db3af0dffc17e65c6a20d925c5a7bd24dec7e 2026-05-07
FileHash-SHA1 75aa215ce3c1902e93c7c36a34c7f12ca4571911 2026-05-07
FileHash-SHA1 7ca9fcdbd712556013319038cf814389968ab258 2026-05-07
FileHash-SHA1 8b3c5b9b867d4be46d1cb5a01d45d67dc8e94082 2026-05-07
FileHash-SHA1 8cf427fd790c3ad166068de81e57efbb932272d4 2026-05-07
FileHash-SHA1 925a8f8d2c6d04e0665f596aff22d863e8256f3f 2026-05-07
FileHash-SHA1 932bed339aa69212c89375b79304b475490b89a0 2026-05-07
FileHash-SHA1 9660798bcba4b6022ca668852add7696ef311c8d 2026-05-07
FileHash-SHA1 9e99a48a9960b14926bb7f3b02e22da2b0ab7280 2026-05-07
FileHash-SHA1 ad7e1c28b064ef8f6003402014c3d0e3370eb58a 2026-05-07
FileHash-SHA1 b1bc968bd4f49d622aa89a81f2150152a41d829c 2026-05-07
FileHash-SHA1 b5abc4899c888c938d03c1af467bed493b889b7b 2026-05-07
FileHash-SHA1 ba23087767e3c84b4b3c7df5dd7243e09d40a8f1 2026-05-07
FileHash-SHA1 ca7788c32da1e4b7863a4fb57d00b55ddacbc7f9 2026-05-07
FileHash-SHA1 cabd2a79a1076a31f21d253635cb039d4329a5e8 2026-05-07
FileHash-SHA1 cc136695639065fab47074d28c55314c66077e90 2026-05-07
FileHash-SHA1 cdf46b4fb3998929e571c12a193742ef92609396 2026-05-07
FileHash-SHA1 cf42262e00c2b1cb0c6f4f90b1f06265fa1c2a4c 2026-05-07
FileHash-SHA1 d1eb23a46d17d68fd92564c2f1f1601764d8e349 2026-05-07
FileHash-SHA1 d6908965a3bf5c4e29d8295414d635e1894cfce3 2026-05-07
FileHash-SHA1 d6aee31631f7abc56b9de8abeccc4108a626b104 2026-05-07
FileHash-SHA1 d9fe0a65fa00cabf61f5120d373a8135e1461f15 2026-05-07
FileHash-SHA1 df3c24f9bfd666761b268073fe06d1cc8d4f82a4 2026-05-07
FileHash-SHA1 e84990cb9bf8e3ab0bcae8a649cb30fe4dc4d767 2026-05-07