
One .NET Builder, Two Malware Families, One Turkish C2 IP
A shared PE import-table hash ties an AgentTesla infostealer and an XWorm RAT to a single .NET build pipeline. Both PEiD-packed assemblies route C2 traffic through a Turkish cloud IP whose RIPE block was registered just 26 days before the April 2026 payload wave. The campaign targets hospitality and technology organisations in Morocco and Turkey.
A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read