PULSE NAME
Fastly: find your muse + keep them on your radar * CAPE Sandbox
WHITE msudosos 2026-05-24 Modified: 2026-05-24
6189
IOCs
HIGH VOLUME
Optics at Altitude is a commercial drone photography and videography service based out of the South Shore, Massachusetts, and beyond, which provides high-quality imagery for a wide-variety of industries and needs.-443 Certificate Caissuers http://secure.globalsign.com/cacert/cloudsslsha2g3.crt 443 Certificate Ocsp http://ocsp2.globalsign.com/cloudsslsha2g3 443 Certificate Serialnumber 0C3B770C982FCBFC7B00B74A 443 Certificate Notafter Apr 14 16:28:35 2019 GMT 443 Certificate Version 3 443 Certificate Subject US 443 Certificate Subject California 443 Certificate Subject San Francisco 443 Certificate Subject Fastly, Inc 443 Certificate Issuer BE 443 Certificate Issuer GlobalSign nv-sa
ip addressstatus codebody lengthkb bodysha256csv textaltitudesouth shoreuas imagerymassachusettsmarshfieldscituatehinghamnorwellhanoverpembrokeepub documentstructure ebookzip documentepubnigel poultondocker deepnielson bookdockersingle bookannadivedive zerodeep divezeroscriptieedgesquarespacedronestitlesecchuamodellinkstaticsupportemarshfield ldapmarshfield sslcertificatecommon nameissuedcharterllc unitedstatesunitednew londondieselcomcast ipderry villagessl certificateencryptcomcast cablecommunicationsbostonkey identifierx509v3 subjectfull namecus odigicertinc cndigicertglobal g2tls rsaca1 validitycus stnewrangecidrnetwork nametypestatuswhois serverentity squar30handlenet198net1980000squar30varick stcitynew yorkstateprovpostalcodeorgtechhandleorgtechreforgabusehandleorgabusereforgnochandleorgnocrefp versionaddress rangespangoogle publicformdoctype htmlgooglepublic dnsheadpublicfooterbodyfile typeascii textpython scriptpythonwrites shellunicode textutf8 textasciiwritessamplepersistencedefense evasioninfonextperforms dnsunitedurlsfoundhttpsmitre attacknetwork infoprocesses extrat1055 processlayer protocolphishingheaders agehomenetet infofile hostingservice domaindomaindns lookupclientendpointperimeterhighinformationaldomain relatedas54113top sourcetop destinationsource sourcestatus domaintcp includeudp includecountry uniteduniqueja3 clientsdestination ipdest portja3 ja3digestcachecaliforniasan franciscofastlyglobalsigntitle pypipackagea domainsacceptshowingentriespreviousdomains showsearchamazon ec2orgnocemailnet75net750000amazon webservicesip routingnethandleamazo4aws rpkihistorical sslcertificatesfirstthumbprintgraph summaryalgorithmnumberissuercus cnletx3 oletsubject publickey infokey algorithmpdf documentadobe portabledocument formatdefaultfile sizemwdbbazaarsha3384ssdeepsha1acrongl integadc4240758shutdownsqlite versionsqlite rollbackutf8jsoncreatesjournalmaliciousresolutionsdatedetectionhostmasteramazon legaldeptamazoncodeemailicann whoisnv adminphonestateprovincetechgatsbygolfhrhrhr
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Norwell
Indicators of Compromise (1 / 6189 total)
All FileHash-SHA256 URL hostname FileHash-MD5 FileHash-SHA1 IPv4 domain CIDR email IPv6 URI CVE SSLCertFingerprint Mutex
TYPEINDICATORDESCRIPTIONCREATED
URI Squarespace.com Length 369951 Strict-Transport-Security max-age=15552000 X-Content-Type-Options nosniff Set-Cookie crumb=BepbvUTMSvhzOGNkZWMxNzY1YmZkMWM1OWNmYjIzZTg5YmI0MDI4;Secure;Path=/ Accept-Ranges bytes Expires Thu, 01 Jan 1970 00:00:00 GMT Vary Accept-Encoding X-Contextid CwvlbPit/TQJdI64O Server Squarespace Etag W/"191800785bf9de165b49474c34fd9ebf--gzip" Date Tue, 03 Oct 2023 16:45:24 GMT X-Frame-Options SAMEORIGIN Content-Type text/html;charset=utf-8 Age 59228 2026-05-24
References (8)
↗ https://vtbehaviour.commondatastorage.googleapis.com/4ac26c6b9045057df857c6994504138c0f11842f2f8cf54baa43830266dcd8fa_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779636742&Signature=0Jmd8OZhEoMcSIRjjLwJ25yOqQqGciJ%2Bi7fIHdY6hAZ943%2BagmRX%2BVjBhTYlLgakIWK9x6Xl42tsN8Zxr1F8%2B9UsiTGouw2FhmIYb0m%2BVstAqLsFZfxFVME005klDDValb5ctckQfmbabxNIeSo3vmrY3IDcc%2FGfcbCW6Iqp9O8UhbCjMEW208ycLJ%2FpHTi1oEgnBzteXKkR%2F6bkcgsXuMmv2zPR5aFV%2FRoRKG4d00Gf ↗ https://vtbehaviour.commondatastorage.googleapis.com/92be0ca27d8a8501a9e3647d71d4aa3cf9cc36c64f4a20f1af181c424cb18a4e_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779638452&Signature=W7GSOCee0L88oD17mS9F7ugbL5UuvCROQTEX3x6zxE6iy%2Fq7d4R2VgKW6vrIVn5INn9P%2Bd4nE9bdDm9hFZfYZtWp2fA8kLWCXUIn9yyEalW3TZiqc3F0VaXhxyOt1z8RxWxNkSJ4q%2FiKIW0UIBNzP3Xb%2BS4HiU1ygKuUsKMrM94faA%2B%2FLvWo8blWHNZjcwJxB6tZER0I70vtmS%2BQUms49SUXQukji6eyu2GeJXt%2BrsVoCx ↗ https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779638734&Signature=xtQED2V3PJ2BlKWGnzpYaInFIj0LtQ5HvUiHwVUnjQrf3nkdgTSOmKHoM8bt07LdXE2gP38gtUEORx1kvCz9WwS2vbQug9jFenQquTV1ymmuBzpRJ3ScOedOXYRUZ0xlMHMSKlEl7EDyuv5oI%2BbysetFZM7njE1QyFexdSfTFnaQLLOfOVYSrLignovntUHgLGqW%2B3pvMPXRK31YQ8G2uah9wKhgHX%2BvBuMBpVk%2Fu%2FB3k9m8DUZK ↗ https://vtbehaviour.commondatastorage.googleapis.com/4ac26c6b9045057df857c6994504138c0f11842f2f8cf54baa43830266dcd8fa_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779638904&Signature=sNLoXHL%2FJqR%2FKpCUpZ3xk1M3w2ix%2F0EztNMcyqjmOrRnpEfN2KtvqN%2BbjjNSOJZ60nF%2Blqn8e%2FCMW1hKcoVai1M%2BJhJchZCA5HTt9I%2FRxELce8C4AtkLuiJkLUydTO2Og2t9T5LjutTKwPeMWArNq9V2OX3NPY4my9NOxSl4azNDj3g2x0Bh%2B4cWRwh2kvoZOqEwQDfwSn1CPloWhsxGvXRWqmxgA5Qg0noBBB4dJGxNwoRKsOWF ↗ https://vtbehaviour.commondatastorage.googleapis.com/4ac26c6b9045057df857c6994504138c0f11842f2f8cf54baa43830266dcd8fa_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779639054&Signature=EEV1EitssGhRiArTQwwI46vPKgz7UanaRN35lG8rZ3aqSaByMgJMG4F%2BBZ3gxHg87k8HJ5ajkCxPtTqsKEvG4C7b9cxkNALabAkhAdOiUgQJcMsP2RYCOcgI%2BpyVmB2ibfAqUo8ZBKCEmQhHPScOb9P3ccZc4cKW7Y%2Fstw5FecP4ddOC%2FimKqWnvBdvueQ0MDbsW20AXvNupNpXm0o09LG91CjzmrHeBMEC%2FTNDhCblMEN2x5oRkK%2Fz7VX ↗ https://vtbehaviour.commondatastorage.googleapis.com/4ac26c6b9045057df857c6994504138c0f11842f2f8cf54baa43830266dcd8fa_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779639078&Signature=tzu4uNt492zFP%2BWaTxQzmPFHxea44DCMQdndQBcAY4YqVoVJ1UV6gsEPg8jB8shQPteUVKvm%2B46kCJpXntnbaegaLcNPwSYtTzGgpwWp13I2RzIYaaQoSBbQRNBF6y8v8Ql3l1FJLbz8vtarUjxrF%2BvvS6LwjT0BzLTAjR%2F5uVviAMddfZphJ1s1wKmfLrEmnZaXomiR8PkhX2nYZMc4jLxkJa%2BomaUKKKMggdRFFCcCLLoe%2Bo ↗ https://vtbehaviour.commondatastorage.googleapis.com/1ea6d01132210234b1da26f181bdcefa423f883ed5b15bd42915b19f68e0604f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779640480&Signature=q34riu0M3M72fz%2FxMMZS6FzxbC%2B8Z1WiO4MLyitIqJjdW95CvaeHBdE50%2BQk2P%2BSgNInq83S55ECox7wveKcpQLScNK4nfIaUO2jJIzkPNEFvO%2F%2BE%2F5CuRCW2H4HWji84nlyWZ7rlT9tvRWINFyCeI0sMYjD2gCovuOfhbEz717%2BUcycH2xU64CcOUIB0JH5kJzclp2AK1E0qdtDf12RLMD5z9Xgy0Wv8ElKSr75JpXomp ↗ https://vtbehaviour.commondatastorage.googleapis.com/1ea6d01132210234b1da26f181bdcefa423f883ed5b15bd42915b19f68e0604f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779640501&Signature=wQUBsRErARJ4flqai%2Fy45lWPUEVVpsxKIVhMiqVCcX3pSfwLxIUQD2aoderkcyUwUNFvaqQQ8jFN2XcbZcQZd2mYBvhNZQ8AxNhD%2BczvWObNrnN9MXmL7Yigcrf1ZfADDnHyk3ReVhUWSr5VW35SrWmrWcksCRf5egYC7hfcS0hqmYx%2F5%2B0iF7zlvKAWT9Iad4FU3zmas1Bri4p8csHlAX5zWpTWHflEQU5H2BddZyie8hc9vloTzOlLZTqmpy