PULSE NAME
CAPE Sandbox- LOTA- Living off the Admin
WHITE msudosos 2026-05-07 Modified: 2026-05-08
2295
IOCs
HIGH VOLUME
The sandbox analysis reveals several high-risk activities that align with modern malware strains. Persistence Mechanisms: The file attempts to modify registry keys and drop executable files in sensitive directories, typical of malware seeking to survive system reboots.Network Communications: It initiates connections to known malicious C2 (Command and Control) infrastructure. This includes resolving DGA (Domain Generation Algorithm) domains and attempting P2P communication.Process Injection: The sample often spawns or injects code into legitimate system processes to evade detection by standard antivirus engines.Data Exfiltration: Observed behavioral signatures include calls to APIs used for harvesting credentials and system metadata, which are then queued for outbound transmission. Network comms 385 HTTP 656 DNS 702 IP 1 JA3. [fcedee2f..] f0r5afo[.exe] 12/28/16 first appearance. 104.31.74.222 Ip I tagged 30 other malcious [exe] in here too. ref file: [e0c]
Indicators of Compromise (24 / 2295 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname CIDR email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 053d057c90af827d0929a6aba7feabcf 2026-05-07
FileHash-MD5 14abc0884f2d6dd0ce426033587b2d45 2026-05-07
FileHash-MD5 173574af7b611cebf4f93ce2ee40f9a2 MD5 of 925a8f8d2c6d04e0665f596aff22d863e8256f3f 2026-05-07
FileHash-MD5 1790548a03cf4a289e1f6cc6a34d39e2 2026-05-07
FileHash-MD5 1f121702ac24ee61bf5f41c99a0c1a0a 2026-05-07
FileHash-MD5 3e455215095192e1b75d379fb187298a MD5 of b1bc968bd4f49d622aa89a81f2150152a41d829c 2026-05-07
FileHash-MD5 453f33c568d61edf493affae2cba089b 2026-05-07
FileHash-MD5 4b1148aee1727b28bf4d7121fe02b486 2026-05-07
FileHash-MD5 4be2c99196650cf40e5a9392a00afeb2 MD5 of 8cf427fd790c3ad166068de81e57efbb932272d4 2026-05-07
FileHash-MD5 57e0b63674a92223447810dd30fe7a1e 2026-05-07
FileHash-MD5 6a01f8a97262a34fbff663e8eae5efb8 2026-05-07
FileHash-MD5 6acfd499b96e738349e3ef87d253897d 2026-05-07
FileHash-MD5 6c397da40e5559b23fd641b11250de43 MD5 of 5f3b8cf2f810b37d78b4ceec1919c37334b9c774 2026-05-07
FileHash-MD5 8014d2b1c4b243d3947454cb611b22f4 2026-05-07
FileHash-MD5 8819f6a5bf79bae10a83d596e9bb870b 2026-05-07
FileHash-MD5 97c421700557a331a31041b81ac3b698 2026-05-07
FileHash-MD5 a00de84cd78718a4a0d66db041715d8a 2026-05-07
FileHash-MD5 b748d44b65054d0a0f2cc80bcff3f1ff 2026-05-07
FileHash-MD5 c0d39a0934709ea84f1a8babbd48661d 2026-05-07
FileHash-MD5 d8305a61bc3a2db879e75f5c9e45d9aa 2026-05-07
FileHash-MD5 dbf675a2e7564fd29ec8b82b29a1a2fe 2026-05-07
FileHash-MD5 eab83bdd6eee1b956e2c8aef88914cc1 2026-05-07
FileHash-MD5 f226782842607f6f8f8361220a8054b2 2026-05-07
FileHash-MD5 e87d34bbff9c939ea07411a523d021c3 2026-05-07