PULSE NAME
Fsysna - Privileged Agent Rufus
WHITE msudosos 2026-05-07 Modified: 2026-05-08
431
IOCs
HIGH VOLUME
The adversary exploits the legitimate operational footprint of Rufus to mask Master Boot Record (MBR) manipulation and bypass heuristic defenses. This indicates a well-versed actor utilizing high-integrity tool-masking to maintain stealth.Technical AnalysisSubversion of Security Policies: The artifact targets HKLM\…\SAFER\CODEIDENTIFIERS to enumerate and likely neutralize Software Restriction Policies (SRP).Direct Disk Manipulation: Exploits the utility’s disk-write primitive to establish persistence at the boot layer, bypassing standard OS-level detection.Privileged Discovery: Forces UAC elevation to conduct exhaustive hardware reconnaissance and volume profiling, facilitating environmental awareness.Heuristic Evasion: masquerades as a trusted unsigned binary to exploit the "administrative whitelist" blind spot in signature-based engines.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 431 total)
All FileHash-SHA256 domain FileHash-MD5 FileHash-SHA1 IPv4 hostname URL email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 f3d7095de1636559aa56ad81b25bbff9 MD5 of 4ff1c75a93b2280dabe75acecade82d644388c9f4412565d846aeb396bfdc133 2026-05-07
FileHash-MD5 3033b36afb4782fe8d41e6d7efda2c3a 2026-05-07
FileHash-MD5 17c4435a27a30ab375247f2c6d053ff0 2026-05-07
FileHash-MD5 3be60851368478173d1ab0b20a20791f 2026-05-07
FileHash-MD5 dc5799565789a9a68cf3e0b11b50272b 2026-05-07
FileHash-MD5 ec3584f3db838942ec3669db02dc908e 2026-05-07