PULSE NAME
Bluesnarfing - Accessibility Feautures Part 2 * VirusTotal Droidy Android Sandbox
WHITE msudosos 2026-05-31 Modified: 2026-05-31
279
IOCs
HIGH VOLUME
A recent Veteran client who was forced to abandon a new smartphone & revert to a legacy model. The target device's pairing registry was flooded with unauthorized "Toyota Corolla" profiles. This disruptive exploit effectively displaced the user, highlighting an emerging threat pattern targeting vulnerable individuals. The vulnerability lies within the smartphone's automated peripheral linking layer. Attackers broadcast spoofed identifiers that the smartphone automatically accepts. This floods and corrupts the local registry database, rendering the device unmanageable. 1 Bluesnarfing: Attackers exploit authentication flaws to gain unauthorized access to internal data, allowing them to copy contacts, text messages, and photos without user permission, 2 Man-in-the-Middle (MitM) Relays: Attackers capture and relay wireless signals over long distances, fooling a phone into believing it is next to a trusted vehicle or accessory when it is miles away, 3 BLE Spoofing Attacks, & 4. Bluejacking.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (279)
All FileHash-MD5 FileHash-SHA1 email hostname URL domain IPv6 FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 04f9da18e198d77fb3f8c3418d19b3f8 2026-05-31
FileHash-MD5 08df71188a92655a7dcd1bb872797741 2026-05-31
FileHash-MD5 0eff6afcbe7e952700ec28f7cca0716d 2026-05-31
FileHash-MD5 26c88c0e916228dda5c9471d3f86bfda 2026-05-31
FileHash-SHA1 9c482ec2a40a4b7efa958226551632ede8685f95 2026-05-31
email domainabuse@cscglobal.com 2026-05-31
hostname whois.corporatedomains.com 2026-05-31
hostname www.toyotafinancial.com 2026-05-31
hostname www.toyotamobility.com 2026-05-31
hostname www.toyotaracing.com 2026-05-31
hostname www.trdusa.com 2026-05-31
URL http://crl.sca1b.amazontrust.com/sca1b.crl 2026-05-31
URL http://crt.sca1b.amazontrust.com/sca1b.crt 2026-05-31
URL http://ocsp.sca1b.amazontrust.com 2026-05-31
URL http://ogp.me/ns/fb 2026-05-31
URL http://schema.org/ 2026-05-31
URL http://www.icann.org/epp#clientTransferProhibited 2026-05-31
URL http://www.w3.org/2000/svg 2026-05-31
URL https://cdn.dg.toyota.com/deploy/websocket-library/1-0/ws-app.min.js 2026-05-31
URL https://icann.org/epp#clientTransferProhibited 2026-05-31
URL https://www.toyota.com 2026-05-31
URL https://www.toyota.com/ 2026-05-31
URL https://www.toyota.com/avanza/ 2026-05-31
URL https://www.toyota.com/content/dam/toyota/brochures/pdf/tss/CFA_TSS_3.pdf 2026-05-31
URL https://www.toyota.com/espanol 2026-05-31
URL https://www.toyota.com/glanza/ 2026-05-31
URL https://www.toyota.com/mirai/features/mpg_other_price/3002/3003/ 2026-05-31
URL https://www.toyota.com/norcal/deals-incentives/ 2026-05-31
URL https://www.toyota.com/owners/parts-service/ 2026-05-31
URL https://www.toyota.com/racing/trd 2026-05-31
URL https://www.toyota.com/search-inventory/model/rav4hybrid/H/ 2026-05-31
URL https://www.toyota.com/supragr/ 2026-05-31
URL https://www.toyota.com/testdrive/ 2026-05-31
URL https://www.toyota.com/usa/operations/manufacturing/tmmk/ 2026-05-31
domain c.audio 2026-05-31
domain c.video 2026-05-31
domain g.call 2026-05-31
domain h.id 2026-05-31
domain icann.org 2026-05-31
domain instagram.com 2026-05-31
domain j.id 2026-05-31
domain k.call 2026-05-31
domain ogp.me 2026-05-31
domain q.style 2026-05-31
domain s.style 2026-05-31
domain schema.org 2026-05-31
domain toyota.com 2026-05-31
domain w.call 2026-05-31
email domainnameadmin@toyota.com 2026-05-31
hostname 08df71188a92655a7dcd1bb872797741.cloudfront.net 2026-05-31
hostname 26c88c0e916228dda5c9471d3f86bfda.cloudfront.net 2026-05-31
hostname access.toyota.com 2026-05-31
hostname cdn.dg.toyota.com 2026-05-31
hostname crl.sca1b.amazontrust.com 2026-05-31
hostname crt.sca1b.amazontrust.com 2026-05-31
hostname fleet.toyota.com 2026-05-31
hostname info.evidon.com 2026-05-31
hostname pdns102.ultradns.biz 2026-05-31
hostname pdns102.ultradns.com 2026-05-31
hostname pdns102.ultradns.net 2026-05-31
hostname pdns102.ultradns.org 2026-05-31
hostname plus.google.com 2026-05-31
hostname pressroom.toyota.com 2026-05-31
hostname www.fueleconomy.gov 2026-05-31
hostname www.icann.org 2026-05-31
hostname www.pinterest.com 2026-05-31
hostname www.toyota-global.com 2026-05-31
hostname www.toyota.com 2026-05-31
hostname www.w3.org 2026-05-31
hostname www.youtube.com 2026-05-31
hostname api.www.toyotamobility.com 2026-05-31
domain corporatedomains.com 2026-05-31
URL https://www.toyotafinancial.com/dss/login 2026-05-31
URL https://www.toyotafinancial.com/dss/secure/manage-recurring-payments 2026-05-31
URL https://www.toyotafinancial.com/dss/secure/payoff-quote 2026-05-31
URL https://www.toyotafinancial.com/dss/secure/profile 2026-05-31
URL https://www.toyotafinancial.com/dss/self-service/verify-identity 2026-05-31
URL https://www.toyotafinancial.com/us/en.html 2026-05-31
URL https://www.toyotafinancial.com/us/en.html/policies/parking 2026-05-31
URL https://www.toyotafinancial.com/us/en/TFS_ThoughtFuel_Blog/the-Lease-end-process.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/end_of_lease_options/early_lease_return.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/end_of_lease_options/faqs.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/apply_for_credit.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/about_this_website/who_can_i_contact_about_problems_with_the_tfs_site.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/billing/i_have_been_receiving_electronic_paperless_billing_statements_for_the_past_3_months_why_did_i_receive_a_paper_billing_statement_in_the_mail_this_month.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/loan_payoff_and_title_lien_release.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/login-faqs/why_isnt_my_password_working.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/online_credit_application/what_happens_after_my_application_is_received.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/planning_tools/faq/payments/how_can_i_get_a_refund_on_a_payment.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/tfs_landing_page.html 2026-05-31
URL https://www.toyotafinancial.com/us/en/vehicle_protection_plan/tire_wheel_protection.html 2026-05-31
IPv6 2600:9000:2201:4c00:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:8c00:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:a000:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:b200:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:c000:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:c800:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:d600:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
IPv6 2600:9000:2201:f000:9:3aa4:d340:93a1 CC=US ASN=AS16509 amazon.com inc 2026-05-31
hostname ns-1038.awsdns-01.org 2026-05-31
hostname ns-1930.awsdns-49.co.uk 2026-05-31
hostname ns-243.awsdns-30.com 2026-05-31
hostname ns-726.awsdns-26.net 2026-05-31
FileHash-SHA1 561130502ae4bb5b48d478d906facf5edf428662 2026-05-31
FileHash-SHA256 048201690167007500d76d7d10d1a7f577c2c7e95fd700bff982c9335a65e1d0 2026-05-31
IPv4 13.226.251.117 2026-05-31
IPv4 13.226.251.37 2026-05-31
IPv4 13.226.251.88 2026-05-31
IPv4 13.226.251.94 2026-05-31
hostname dzo9ysms19bgt.cloudfront.net 2026-05-31
IPv4 1.3.6.1 2026-05-31
IPv4 129.2.4.2 2026-05-31
IPv4 2.23.140.1 2026-05-31
URL http://crl.r2m04.amazontrust.com/r2m04.crl 2026-05-31
URL http://crt.r2m04.amazontrust.com/r2m04.cer 2026-05-31
URL http://ocsp.r2m04.amazontrust.com 2026-05-31
hostname crl.r2m04.amazontrust.com 2026-05-31
hostname crt.r2m04.amazontrust.com 2026-05-31
hostname ocsp.r2m04.amazontrust.com 2026-05-31
hostname whois.markmonitor.com 2026-05-31
hostname akatest.www.toyota.com 2026-05-31
hostname origin.www.toyota.com 2026-05-31
FileHash-MD5 428b3b2a8ea46e12175c2c44c4b4ca24 2026-05-31
FileHash-MD5 96979c5dbe3119454315ed6b6aaa54a9 2026-05-31
FileHash-MD5 9f0e2bbc95834d16a7705e2ea0d908ec 2026-05-31
FileHash-MD5 ab987ff35982d2500c8164cb31fc153d 2026-05-31
FileHash-SHA1 b213090c5204bf94318f4ef0539a38b487d10368 2026-05-31
hostname crashlytics.installation.id 2026-05-31
IPv4 3.1.0.2 2026-05-31
URL https://assets.adobedtm.com/b213090c5204bf94318f4ef0539a38b487d10368/scripts/satellite-559717b931343800140000fc.json 2026-05-31
URL https://assets.adobedtm.com/b213090c5204bf94318f4ef0539a38b487d10368/scripts/satellite-559717b933353400140008e8.json 2026-05-31
URL https://smetrics.toyota.com/id 2026-05-31
hostname assets.adobedtm.com 2026-05-31
hostname com.a.a.al 2026-05-31
hostname com.crashlytics.sdk.android 2026-05-31
hostname smetrics.toyota.com 2026-05-31
FileHash-MD5 5c57034e20fe4133867e3d26b821ffe0 2026-05-31
FileHash-SHA1 23e00e826b0d8d79661ae5f84fe56716f4efbf32 2026-05-31
FileHash-SHA1 b3c3b5cf6a259b9b2dc9abed729d22cba71de58e 2026-05-31
FileHash-SHA256 18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef 2026-05-31
domain build-data.properties 2026-05-31
domain crashlytics-build.properties 2026-05-31
hostname com.crashlytics.sdk.android.crashlytics-core.properties 2026-05-31
hostname io.fabric.sdk.android.fabric.properties 2026-05-31
URL http://origin.www.toyota.com/ownerstouch/content/events 2026-05-31
URL http://plus.google.com/ 2026-05-31
URL https://auth3.toyota.com/toyota-owners-theme/json/how-to-videos/youtube/featured.json 2026-05-31
URL https://auth3.toyota.com/toyota-owners-theme/mobile/json/dashboard-icons/dashboard-icons-disclaimers.json 2026-05-31
URL https://auth3.toyota.com/toyota-owners-theme/mobile/json/youtube/youtube_feeds.json 2026-05-31
domain de.properties 2026-05-31
domain icudt46l.zip 2026-05-31
domain libsqlcipher.so 2026-05-31
hostname android.intent.action.my 2026-05-31
hostname android.permission.camera 2026-05-31
hostname android.permission.read 2026-05-31
hostname auth3.toyota.com 2026-05-31
hostname com.crashlytics.sdk.android.answers.properties 2026-05-31
hostname com.crashlytics.sdk.android.beta.properties 2026-05-31
hostname com.crashlytics.sdk.android.crashlytics.properties 2026-05-31
hostname com.google.android.providers.gsf.permission.read 2026-05-31
domain adobedtm.com 2026-05-31
domain crashlytics.com 2026-05-31
hostname da21vz4r4dvh6.cloudfront.net 2026-05-31
hostname e7808.g.akamaiedge.net 2026-05-31
hostname eigws.toyota.com 2026-05-31
hostname origin.ssl.toyota.com 2026-05-31
hostname rupn4.x.incapdns.net 2026-05-31
hostname settings.crashlytics.com 2026-05-31
hostname toyota.com.ssl.d1.sc.omtrdc.net 2026-05-31
FileHash-SHA256 116fd4dc47310e780234271317c561b6a3ffa082f88372e07c6a86fdc5359464 2026-05-31
FileHash-SHA256 14da3022f89b695a4cc374b30ae6d1a5db407a8225c369fa0b46d4e4a17c3666 2026-05-31
FileHash-SHA256 1d915bdd91aa63a6acda12a6b73eb4840ebf83fc11558f62736ad278eb9c85cd 2026-05-31
FileHash-SHA256 63b2445a631f7fed9e5533a29011e797876df3584bb3470ddf8854b2bbb58d0c 2026-05-31
FileHash-SHA256 8bf715fbf4c33436cce55f9269fc331eb255c322233cdedae4456297b338aaf0 2026-05-31
FileHash-SHA256 90922cf3d50d155e5faecec3e926ac861781efa0768c51d372f92b4ad279fa9b 2026-05-31
FileHash-SHA256 a111c0751e294cd88b0a418c1b12d8a544961000d720db185ebc2e19fb9360f7 2026-05-31
FileHash-SHA256 a64943b0a3e7e5734e94fe6d71173a92b8c0f83ef650305b44ac438b07b88cc1 2026-05-31
FileHash-SHA256 d54ab767ddad250736025c3aed2478ec35f3eb88b06dff4b5152f24818c91b59 2026-05-31
FileHash-SHA256 fef6d92a32b57950b9df13a42a0e96e4a92451d2ecf9b6898efaa0240424a429 2026-05-31
IPv4 107.154.76.95 CC=US ASN=AS19551 incapsula inc 2026-05-31
IPv4 69.25.174.195 CC=US ASN=AS7116 toyota motor sales usa 2026-05-31
IPv4 107.20.220.57 2026-05-31
IPv4 107.21.118.233 2026-05-31
IPv4 107.22.216.92 2026-05-31
IPv4 108.128.130.224 2026-05-31
IPv4 143.204.101.11 2026-05-31
IPv4 143.204.101.113 2026-05-31
IPv4 143.204.101.126 2026-05-31
IPv4 143.204.101.30 2026-05-31
IPv4 174.129.0.44 2026-05-31
IPv4 184.73.159.232 2026-05-31
IPv4 52.31.190.58 2026-05-31
IPv4 52.49.100.189 2026-05-31
IPv4 54.243.98.151 2026-05-31
IPv4 54.83.193.68 2026-05-31
IPv4 54.83.37.39 2026-05-31
IPv4 92.122.200.39 2026-05-31
URL https://access-sta.telematics.net/openam/saml2/jsp/spSSOInit.jsp?idpEntityID=https://efed-stg10.qa.toyota.com/oam/fed&metaAlias=/toyota/TO/sp 2026-05-31
hostname access-sta.telematics.net 2026-05-31
FileHash-SHA1 0b8464eae298da2d9ec5a12271309acb25e25465 2026-05-31
hostname www.michaellapeantoyotamotorsales.com 2026-05-31
URL http://dev.virtualearth.net/REST/v1/Locations/ 2026-05-31
URL http://dev.virtualearth.net/REST/v1/Locations/US 2026-05-31
URL http://docs.google.com/gview?embedded=true&url= 2026-05-31
URL http://gdata.youtube.com/feeds/api/videos/ 2026-05-31
URL http://next.ws.toyota.com 2026-05-31
URL http://next.ws.toyota.com/DISREST/rest/getDealers 2026-05-31
URL http://next.ws.toyota.com/toomsServices/rest/searchoffers/V1 2026-05-31
URL http://schemas.android.com/apk/res/android 2026-05-31
URL http://touch.toyota.com/help/contact-noheader.html 2026-05-31
URL http://touch.toyota.com/help/legal-noheader.html 2026-05-31
URL http://touch.toyota.com/help/privacy-noheader.html 2026-05-31
URL http://toyota.custhelp.com/app/answers/list/p/187 2026-05-31
URL http://www.google.com 2026-05-31
URL http://www.toyota.com 2026-05-31
URL http://www.youtube.com/watch?v= 2026-05-31
URL https://app.igodigital.com/api/v1/collect/process_batch 2026-05-31
URL https://auth3.toyota.com 2026-05-31
URL https://auth3.toyota.com/toyota-owners-online-portlet/serviceoffers/viewServiceOffersImage?imageType=offerImage&offerId= 2026-05-31
URL https://auth3.toyota.com/toyota-owners-theme/json/how-to-videos/youtube/ 2026-05-31
URL https://consumer.exacttargetapis.com/device/v1/ 2026-05-31
URL https://consumer.exacttargetapis.com/device/v1/event/analytic 2026-05-31
URL https://consumer.exacttargetapis.com/device/v1/location/ 2026-05-31
URL https://consumer.exacttargetapis.com/device/v1/registration 2026-05-31
URL https://e.crashlytics.com/spi/v2/events 2026-05-31
URL https://pagead2.googlesyndication.com/pagead/gen_204?id=gmob-apps 2026-05-31
URL https://settings.crashlytics.com/spi/v2/platforms/android/apps/%s/settings 2026-05-31
URL https://stage.app.igodigital.com/api/v1/collect/qa/s1qa1/process_batch 2026-05-31
URL https://stage.app.igodigital.com/api/v1/collect/qa/s1qa3/process_batch 2026-05-31
URL https://staging.toyota.com/ownerstouch 2026-05-31
URL https://toyota.custhelp.com/app/answers/list/p/187 2026-05-31
URL http://s.recs.igodigital.com/a/v2/%s/%s/recommend.json 2026-05-31
hostname app.igodigital.com 2026-05-31
hostname consumer.exacttargetapis.com 2026-05-31
hostname dev.virtualearth.net 2026-05-31
hostname docs.google.com 2026-05-31
hostname e.crashlytics.com 2026-05-31
hostname efed-stg10.qa.toyota.com 2026-05-31
hostname gdata.youtube.com 2026-05-31
hostname next.ws.toyota.com 2026-05-31
hostname pagead2.googlesyndication.com 2026-05-31
hostname s.recs.igodigital.com 2026-05-31
hostname schemas.android.com 2026-05-31
hostname stage.app.igodigital.com 2026-05-31
hostname staging.toyota.com 2026-05-31
hostname touch.toyota.com 2026-05-31
hostname toyota.custhelp.com 2026-05-31
hostname com.toyota.towners.view.splashactivity.com 2026-05-31
URL http://s7.prototype.g.call/ 2026-05-31
URL https://ho.u.g.call/ 2026-05-31
URL http://cy.prototype.k.call 2026-05-31
URL http://dv.l.k.call/ 2026-05-31
URL https://cy.prototype.k.call 2026-05-31
URL https://o.b.k.call/ 2026-05-31
URL https://t.prototype.k.call/ 2026-05-31
URL http://i.s.style/ 2026-05-31
URL https://i.s.style/ 2026-05-31
hostname www.tmobile.com 2026-05-31
hostname www.walmart.com 2026-05-31
FileHash-SHA256 04419d27b782bd3695f0b5958a5e82548072f5605b545de419d32e561aeeabd6 2026-05-31
FileHash-SHA256 0e6ff63d0684b7323e039273b5024439ccdf5c60bc7056740e6ff0875b6b34c0 2026-05-31
FileHash-SHA256 1213baff29fcdd94d63835d6cb97881d928be00f28d0631c68c5e7c8a38b3898 2026-05-31
FileHash-SHA256 306856a5317bead533b3ef702f1a6ba3eb5a7c239c5dac12eeb7b90cf84b7be6 2026-05-31
FileHash-SHA256 37dd3641cd983dfd7f6dc007ee4379be1120284db0d6330ae68e7161d7c5b719 2026-05-31
FileHash-SHA256 45013f2073d7d6c22c5b05d2052f040513a1ef4cd757ad8fb9a947367c6d5b71 2026-05-31
FileHash-SHA256 53fb79f2674e8bf97352a51314f753c6a6e3c4c2822a5b7bd5e10fea8bd0e5e9 2026-05-31
FileHash-SHA256 728badaa02d9dad4b432d1238a75b566e2717c300490706e6748c4cb102e8f00 2026-05-31
FileHash-SHA256 877c96aef33dffccba8590189dca8b7bd4113c4c1c0513faea7cb0880ed0d2c9 2026-05-31
FileHash-SHA256 9599b4c7106a1b94f28fdd57e1e329b951dd1b75d51c2365e4c22a3634b81749 2026-05-31
FileHash-SHA256 a52f8838faa08a12a6a14689ee308c37e1bb0567dafe1fbb4bdca0b608d04447 2026-05-31
FileHash-SHA256 a5763c035b8895f80c62810e860244e919248e63f870c0f43c06bd07e4af2deb 2026-05-31
FileHash-SHA256 a5f9c57d25865b8b94eac1b7f93e33e3eff047dbba78d22ae793debb37d44368 2026-05-31
FileHash-SHA256 b2983ce1a9233b6ad528f916fb8a1ded85765e1dcbb8d4c5c435fc869442ccd8 2026-05-31
FileHash-SHA256 c954d8ffb0e26e291d27d4b237370e25b327e8303fbe79666502c2f58235d0e9 2026-05-31
FileHash-SHA256 d8bf0f3712dc6825c3667ff8bee9f8889059449342bb51d016db87398a0c2eff 2026-05-31
FileHash-SHA256 e38d2610ad5aa9b558e5feba79bbd388f85af0150c6afc14460e36ba4246ae90 2026-05-31
FileHash-SHA256 f29493b83b186595c68be3a9a4c11067475da43164789ab579ef7a4591cbb69a 2026-05-31
FileHash-SHA256 fb73b4119f2c611751dc491a186eb66a6f10ef4210fe54c4e7b1cd440d1483ae 2026-05-31
FileHash-SHA256 fe93947d8bd8a5a36d69a62ece6fcac47fe5e6c3436c48c58f5a5c06f34c9ff1 2026-05-31