
Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged
A packed .NET AgentTesla dropper disguised as a Q88 vessel-particulars document is hitting thirteen countries, filtering out sandbox environments via an ip-api.com geolocation check before harvesting credentials. A follow-up indicator update adds two entirely uncharacterised file hashes, weakening rather than strengthening the evidentiary base, while an APT29/Remcos attribution in the threat metadata conflicts with sandbox-confirmed AgentTesla findings.
A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read