PULSE NAME
* Cross-Platform iOS Curveball Crypto Forgery Exploit * CAPE Sandbox
WHITE msudosos 2026-05-18 Modified: 2026-05-20
864
IOCs
HIGH VOLUME
Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3 * SHA-1: d73716914eb0b2a0211... 2. Malformed Mathematical Parsing Architecture The js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks. * Script Target String Hash: 57c8a0597dcd4... -Internal File Path Queried -Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries. -Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f. -Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 864 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6816bd15813549fa95a543dc7593b2a3 2026-05-18
FileHash-MD5 091f51a7a1c3a4504a224cc081ce9cee 2026-05-18
FileHash-MD5 32793999d4d214d4dafc0a16ebf6c747 2026-05-18
FileHash-MD5 390486481d34bd03a492678e62891cff 2026-05-18
FileHash-MD5 46f5131e766d248db0248a86c494b71c 2026-05-18
FileHash-MD5 5919f6108f098e14c2f37619021ebd4d 2026-05-18
References (3)
↗ https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo ↗ https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6 ↗ https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed