PULSE NAME
Fsysna - Privileged Agent Rufus
WHITE msudosos 2026-05-07 Modified: 2026-05-08
431
IOCs
HIGH VOLUME
The adversary exploits the legitimate operational footprint of Rufus to mask Master Boot Record (MBR) manipulation and bypass heuristic defenses. This indicates a well-versed actor utilizing high-integrity tool-masking to maintain stealth.Technical AnalysisSubversion of Security Policies: The artifact targets HKLM\…\SAFER\CODEIDENTIFIERS to enumerate and likely neutralize Software Restriction Policies (SRP).Direct Disk Manipulation: Exploits the utility’s disk-write primitive to establish persistence at the boot layer, bypassing standard OS-level detection.Privileged Discovery: Forces UAC elevation to conduct exhaustive hardware reconnaissance and volume profiling, facilitating environmental awareness.Heuristic Evasion: masquerades as a trusted unsigned binary to exploit the "administrative whitelist" blind spot in signature-based engines.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (79 / 431 total)
All FileHash-SHA256 domain FileHash-MD5 FileHash-SHA1 IPv4 hostname URL email
TYPEINDICATORDESCRIPTIONCREATED
hostname help.jetpack.net 2026-05-07
hostname ln-0007.ln-msedge.net 2026-05-07
hostname wiki.gnumed.de 2026-05-07
hostname a1666.dscr.akamai.net 2026-05-07
hostname assets.msn.com 2026-05-07
hostname nsis.sf.net 2026-05-07
hostname www.gnu.org 2026-05-07
hostname cbt.bss.bs 2026-05-07
hostname www.syslinux.org 2026-05-07
hostname a-0003.a-msedge.net 2026-05-07
hostname a1961.g2.akamai.net 2026-05-07
hostname a767.dspw65.akamai.net 2026-05-07
hostname api-msn-com.a-0003.a-msedge.net 2026-05-07
hostname api.msn.com 2026-05-07
hostname atm-settingsfe-prod-geo2.trafficmanager.net 2026-05-07
hostname azureedge-t-prod.trafficmanager.net 2026-05-07
hostname bg.microsoft.map.fastly.net 2026-05-07
hostname client.wns.windows.com 2026-05-07
hostname code.google.com 2026-05-07
hostname crl.comodoca.com 2026-05-07
hostname crl.comodoca.com.cdn.cloudflare.net 2026-05-07
hostname crl.root-x1.letsencrypt.org.edgekey.net 2026-05-07
hostname crt.comodoca.com 2026-05-07
hostname crt.comodoca.com.cdn.cloudflare.net 2026-05-07
hostname ctldl.windowsupdate.com 2026-05-07
hostname d.symcb.com 2026-05-07
hostname doc.sch130.nsc.ru 2026-05-07
hostname download.windowsupdate.com.edgesuite.net 2026-05-07
hostname e2fsprogs.sourceforge.net 2026-05-07
hostname e8652.dscx.akamaiedge.net 2026-05-07
hostname fe3.delivery.mp.microsoft.com 2026-05-07
hostname fe3cr.delivery.mp.microsoft.com 2026-05-07
hostname fp2e7a.wpc.2be4.phicdn.net 2026-05-07
hostname fp2e7a.wpc.phicdn.net 2026-05-07
hostname freedos.sourceforge.net 2026-05-07
hostname glb.cws.prod.dcat.dsp.trafficmanager.net 2026-05-07
hostname glb.sls.prod.dcat.dsp.trafficmanager.net 2026-05-07
hostname login.live.com 2026-05-07
hostname login.msa.msidentity.com 2026-05-07
hostname maps-win-com-cdn.afd.azureedge.net 2026-05-07
hostname maps-win-com-cdn.azureedge.net 2026-05-07
hostname maps.windows.com 2026-05-07
hostname ms-sys.sourceforge.net 2026-05-07
hostname ncsi-geo.trafficmanager.net 2026-05-07
hostname ocsp.comodoca.com 2026-05-07
hostname ocsp.comodoca.com.cdn.cloudflare.net 2026-05-07
hostname ocsp.digicert.com 2026-05-07
hostname ocsp.edge.digicert.com 2026-05-07
hostname part-0010.t-0009.t-msedge.net 2026-05-07
hostname prdv4a.aadg.msidentity.com 2026-05-07
hostname processhacker.sourceforge.net 2026-05-07
hostname rufus.akeo.ie 2026-05-07
hostname s.symcb.com 2026-05-07
hostname schemas.microsoft.com 2026-05-07
hostname secure.comodo.net 2026-05-07
hostname settings-prod-eus2-2.eastus2.cloudapp.azure.com 2026-05-07
hostname settings-win.data.microsoft.com 2026-05-07
hostname shed.dual-low.part-0010.t-0009.t-msedge.net 2026-05-07
hostname sls.update.microsoft.com 2026-05-07
hostname slscr.update.microsoft.com 2026-05-07
hostname svn.reactos.org 2026-05-07
hostname ts-aia.ws.symantec.com 2026-05-07
hostname ts-crl.ws.symantec.com 2026-05-07
hostname wns.notify.trafficmanager.net 2026-05-07
hostname wu-bg-shim.trafficmanager.net 2026-05-07
hostname www.7-zip.org 2026-05-07
hostname www.busybox.net 2026-05-07
hostname www.codeguru.com 2026-05-07
hostname www.freedos.org 2026-05-07
hostname www.gnupg.org 2026-05-07
hostname www.msftconnecttest.com 2026-05-07
hostname www.msftncsi.com.edgesuite.net 2026-05-07
hostname www.reactos.org 2026-05-07
hostname www.ridgecrop.demon.co.uk 2026-05-07
hostname www.sysinternals.com 2026-05-07
hostname www.tm.lg.prod.aadmsa.trafficmanager.net 2026-05-07
hostname www.tm.v4.a.prd.aadg.trafficmanager.net 2026-05-07
hostname www.w3.org 2026-05-07
hostname x1.c.lencr.org 2026-05-07