PULSE NAME
* BumbleBee Loader * CAPE Sandbox - 5/1/25
WHITE msudosos 2026-05-15 Modified: 2026-05-17
1005
IOCs
HIGH VOLUME
Compilation Timestamp 2025-05-01 18:04:59 UTC Entry Point 527** Contained Sections 7 Written in C++, this malware functions as a first-stage backdoor designed to establish an initial foothold before continuing its stealthy attack to move into MAAS, operations, and development. Bumblebee is primarily delivered via phishing emails—often disguised as invoices—but its scope also includes PDFs, voicemails, zip files, and images. The malware is highly evasive, routinely checking its environment, executing payloads, and creating LOLBins. Related to Operation Endgame, it notably disrupted regsvr32.exe in May 2024. This specific variant was created on May 1, 2025, and appeared to be set into operation on May 5, 2025—interestingly, just one day after Microsoft changed its DKIM, SPF, and DMARC rules. ed76019fbae16d3992d1939c38d620185f4520e128f80983a00cadc6a9c3b509 2025-05-05_77aa5cace886af5e61db8eb4c4cea57e_black-basta_cobalt-strike_satacom
Indicators of Compromise (92 / 1005 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 SSLCertFingerprint URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0119e81be9a14cd8e22f40ac118c687ecba3f4d8 2026-05-15
FileHash-SHA1 01bcbd134a76ccd4f3badb5f4056abedcff60734 2026-05-15
FileHash-SHA1 023c4f1159a2a05420f68daf939b9ac2b04ab082 SHA1 of 128a583e821e52b595eb4b3dda17697d3ca456ee72945f7ecce48ededad0e93c 2026-05-15
FileHash-SHA1 050fc5ccd92af4fbb3047be40202d062f9958e57 2026-05-15
FileHash-SHA1 0563b8630d62d75abbc8ab1e4bdfb5a899b24d43 2026-05-15
FileHash-SHA1 06f1aa330b927b753a40e68cdf22e34bcbef3352 2026-05-15
FileHash-SHA1 07311208d4849f821e8af25a89a9985c4503fbd8 2026-05-15
FileHash-SHA1 07e032e020b72c3f192f0628a2593a19a70f069e 2026-05-15
FileHash-SHA1 109f1caed645bb78b3ea2b94c0697c740733031c 2026-05-15
FileHash-SHA1 11949ebc05d24ab39d86193b6b6fcff3e4733cfd 2026-05-15
FileHash-SHA1 15948cd5a601907ff773d0b48e493adf0d38a1a6 2026-05-15
FileHash-SHA1 18f7c1fcc3090203fd5baa2f861a754976c8dd25 2026-05-15
FileHash-SHA1 1ba000ec2cec543c4e27228d4cd4aef8ae1e8408 2026-05-15
FileHash-SHA1 1f24c630cda418ef2069ffad4fdd5f463a1b69aa 2026-05-15
FileHash-SHA1 21dd10ed31bb32d5700bac8d92deaba9f6b723bb SHA1 of 4be23384ec40d408b5fd5b26045f64369743f5bd56467007c3df75152b6d1efb 2026-05-15
FileHash-SHA1 243e9dd038d3d68c67d42c0c4ba80622c2a56246 2026-05-15
FileHash-SHA1 245c97df7514e7cf2df8be72ae957b9e04741e85 2026-05-15
FileHash-SHA1 2796bae63f1801e277261ba0d77770028f20eee4 2026-05-15
FileHash-SHA1 2b8f1b57330dbba2d07a6c51f70ee90ddab9ad8e 2026-05-15
FileHash-SHA1 31f9fc8ba3805986b721ea7295c65b3a44534274 2026-05-15
FileHash-SHA1 3601e51a96cc845e7c427800a84b218ce5c232d1 2026-05-15
FileHash-SHA1 38baef74bdd2e941ccd321f91bfd49dacc6a3cb6 2026-05-15
FileHash-SHA1 3b1efd3a66ea28b16697394703a72ca340a05bd5 2026-05-15
FileHash-SHA1 3cedfb74d44f2e84198d23075aef16c34a668ceb 2026-05-15
FileHash-SHA1 43ff8bd22afcac065555219aa2c1b3b44f3a7827 2026-05-15
FileHash-SHA1 470f2715fafd5cafa79e8f3b0a5434a6da78a1ba 2026-05-15
FileHash-SHA1 4d9e921feaee5fa70181eba99054ffa7b6c9bb3f 2026-05-15
FileHash-SHA1 4ec500e04e5b2ce3479e54e2494e8f987594435f 2026-05-15
FileHash-SHA1 4efc31460c619ecae59c1bce2c008036d94c84b8 2026-05-15
FileHash-SHA1 4fcb85d0c150a59ee4ccb49423a27b03629f4b59 2026-05-15
FileHash-SHA1 4ff3a7a9d9ca005b5659b55d8cd064d2eb708b1a 2026-05-15
FileHash-SHA1 514bdded73c49b95dd07444e05c898dc2f324611 SHA1 of 29d067c66e55202eb1e466d8fd5b982d44ab0dc9b9be771353d574c5e82bdb73 2026-05-15
FileHash-SHA1 51501fbfce69189d609cfaf140c576755dcc1fdf 2026-05-15
FileHash-SHA1 5e3004cba3e03495a95f07c0015aab1266b4d78d 2026-05-15
FileHash-SHA1 5fb7ee0633e259dbad0c4c9ae6d38f1a61c7dc25 2026-05-15
FileHash-SHA1 63f51eb5dafeb24327e3bcb63828336c920b4fcd SHA1 of f3501ebce24205f3dc54192cd917eab9a899fe936570650253d4c1466383eff1 2026-05-15
FileHash-SHA1 64ce9b5d5f07395935df95d4a0f06760319224a2 2026-05-15
FileHash-SHA1 653cc1c82ba6240b0186623724aec3287e9bc232 2026-05-15
FileHash-SHA1 66c18b0406201c3cfbba6e239ab9ee3dbb3be07d 2026-05-15
FileHash-SHA1 683f452d706d54cdf9323c187a820cb941a10a28 2026-05-15
FileHash-SHA1 6fd102eb3e0b0e6eef08118d71f28702d1a9067c 2026-05-15
FileHash-SHA1 73a5e64a3bff8316ff0edccc618a906e4eae4d74 2026-05-15
FileHash-SHA1 742c3192e607e424eb4549542be1bbc53e6174e2 2026-05-15
FileHash-SHA1 787b9abd40660f72bbc9db23227961ced55f4f66 2026-05-15
FileHash-SHA1 7b0f360b775f76c94a12ca48445aa2d2a875701c 2026-05-15
FileHash-SHA1 7e04de896a3e666d00e687d33ffad93be83d349e 2026-05-15
FileHash-SHA1 7f88cd7223f3c813818c994614a89c99fa3b5247 2026-05-15
FileHash-SHA1 8094640eb5a7a1ca119c1fddd59f810263a7fbd1 2026-05-15
FileHash-SHA1 8278f9539463f0a45009287f0516098cb7a15406 2026-05-15
FileHash-SHA1 830d4905b70bbff98479acb72c79176a2c3f0c1f 2026-05-15
FileHash-SHA1 83daf591c049f977879e5114c5fea9bbbfa0ad7b 2026-05-15
FileHash-SHA1 8cf427fd790c3ad166068de81e57efbb932272d4 2026-05-15
FileHash-SHA1 8f43288ad272f3103b6fb1428485ea3014c0bcfe 2026-05-15
FileHash-SHA1 925a8f8d2c6d04e0665f596aff22d863e8256f3f 2026-05-15
FileHash-SHA1 92b46c76e13054e104f230517e6e504d43ab10b5 2026-05-15
FileHash-SHA1 95b918f3f4c057fb9c878c8cc5e502c0bd9e54c0 2026-05-15
FileHash-SHA1 99beeb17bfc69e8370036f9457edb4d6812b22e2 SHA1 of 9c7fc855d9d1614e70705c7dcc6f4ac3cdcab5adfeb6a67d382f5ade09eadc15 2026-05-15
FileHash-SHA1 9ddb35fb947e55d340525ab38a635a5a705d6fe0 SHA1 of 12b3f8ad651f7b45d5aee6692bf26394ad8f8ece5c91d5df1aeba56405278d09 2026-05-15
FileHash-SHA1 a25a39dca11cdc195c9ecd49e95657a3e4fe3215 2026-05-15
FileHash-SHA1 a377d1b1c0538833035211f4083d00fecc414dab 2026-05-15
FileHash-SHA1 a43489159a520f0d93d032ccaf37e7fe20a8b419 2026-05-15
FileHash-SHA1 a8985d3a65e5e5c4b2d7d66d40c6dd2fb19c5436 2026-05-15
FileHash-SHA1 a8c841a943d0c1493db3cb1e5e98f9df8f3feb72 SHA1 of 7850ae281e95ca3db544cf69e5811141f11758b8d0efe5015ce9b71731b3108f 2026-05-15
FileHash-SHA1 ad7e1c28b064ef8f6003402014c3d0e3370eb58a 2026-05-15
FileHash-SHA1 b1bc968bd4f49d622aa89a81f2150152a41d829c 2026-05-15
FileHash-SHA1 be36a4562fb2ee05dbb3d32323adf445084ed656 2026-05-15
FileHash-SHA1 c1eb0cde2406b6af565f825dcd492589d40ab644 2026-05-15
FileHash-SHA1 cabd2a79a1076a31f21d253635cb039d4329a5e8 2026-05-15
FileHash-SHA1 cdd4eeae6000ac7f40c3802c171e30148030c072 2026-05-15
FileHash-SHA1 d07d3c0b0cec9590d4d3f555332b3d58aaa055a0 2026-05-15
FileHash-SHA1 d1eb23a46d17d68fd92564c2f1f1601764d8e349 2026-05-15
FileHash-SHA1 d4de20d05e66fc53fe1a50882c78db2852cae474 2026-05-15
FileHash-SHA1 d519f1222ea3c90290b6d07a57f5a95e82a9919a 2026-05-15
FileHash-SHA1 d559a586669b08f46a30a133f8a9ed3d038e2ea8 2026-05-15
FileHash-SHA1 d69b561148f01c77c54578c10926df5b856976ad 2026-05-15
FileHash-SHA1 d7a03141d5d6b1e88b6b59ef08b6681df212c599 2026-05-15
FileHash-SHA1 dac9024f54d8f6df94935fb1732638ca6ad77c13 2026-05-15
FileHash-SHA1 db0843b89a84fb37efd3c76168bcb303174aac29 SHA1 of e21f4c40c29be0b115463e7bb8a365946a4afc152b9fff602abd41c6e0ce68a2 2026-05-15
FileHash-SHA1 dd2314752984329a4ea0180e5786b57c8ec5fd3a SHA1 of e7606fb73c8c73f7993583e5cb06cbf521d1aac596ab337ed5ea6d1ed98107de 2026-05-15
FileHash-SHA1 ddfb16cd4931c973a2037d3fc83a4d7d775d05e4 2026-05-15
FileHash-SHA1 df3c24f9bfd666761b268073fe06d1cc8d4f82a4 2026-05-15
FileHash-SHA1 e54976a989e830310999a0d67c3b526f28c818c7 SHA1 of 2ad2c963264b54ff2b34ac378e6461a06a7fe979cf0021ec8e46c86f29ffe86e 2026-05-15
FileHash-SHA1 ebb6463c41dd5417d7857eab14de3004e2d4131b 2026-05-15
FileHash-SHA1 efe6fa11a09dedac8964735f87877ba477bec341 2026-05-15
FileHash-SHA1 f30050af81f687361d8b509f38f62fcea8601422 2026-05-15
FileHash-SHA1 f59782a4923a30118b97e01a7f8db69b92d8382a 2026-05-15
FileHash-SHA1 f73d33677f5c61deb8a736e8dde14e1924e0b0dc 2026-05-15
FileHash-SHA1 fae62faf96223ce7a3e6f7389a9b14b890c24789 2026-05-15
FileHash-SHA1 fee449ee0e3965a5246f000e87fde2a065fd89d4 2026-05-15
FileHash-SHA1 579b8c30100421557b93994aa6395f426efc0cb8 2026-05-15
FileHash-SHA1 839d7893943782ee803536a47f1d4de160314f85 2026-05-15
FileHash-SHA1 e859a546f73b673a44a1131ad7c007572158488c 2026-05-15