PULSE NAME
Fsysna - Privileged Agent Rufus
WHITE msudosos 2026-05-07 Modified: 2026-05-08
431
IOCs
HIGH VOLUME
The adversary exploits the legitimate operational footprint of Rufus to mask Master Boot Record (MBR) manipulation and bypass heuristic defenses. This indicates a well-versed actor utilizing high-integrity tool-masking to maintain stealth.Technical AnalysisSubversion of Security Policies: The artifact targets HKLM\…\SAFER\CODEIDENTIFIERS to enumerate and likely neutralize Software Restriction Policies (SRP).Direct Disk Manipulation: Exploits the utility’s disk-write primitive to establish persistence at the boot layer, bypassing standard OS-level detection.Privileged Discovery: Forces UAC elevation to conduct exhaustive hardware reconnaissance and volume profiling, facilitating environmental awareness.Heuristic Evasion: masquerades as a trusted unsigned binary to exploit the "administrative whitelist" blind spot in signature-based engines.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 431 total)
All FileHash-SHA256 domain FileHash-MD5 FileHash-SHA1 IPv4 hostname URL email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 6a55e1445c1c915664fba385828c5a0078fe460d SHA1 of 4ff1c75a93b2280dabe75acecade82d644388c9f4412565d846aeb396bfdc133 2026-05-07
FileHash-SHA1 a0b95d81464686310d4a1076693f0fae191e11a7 2026-05-07
FileHash-SHA1 2dc49363f8e6d99f2ad84739e91750f8207bc920 2026-05-07
FileHash-SHA1 5fa8ae199ed8c3b6fe1fc164e2587ded61852efc 2026-05-07
FileHash-SHA1 8dceb96874d5c6425ebb81bfee587244c89416da 2026-05-07
FileHash-SHA1 ea08ce11366c3b80c42a1bc7098dbd2e2a017c1f 2026-05-07