MB-03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e
high
📛 Threat Title
Unknown: pulse.jar.github-Course23sz
Description
File type: zip. Size: 9231196 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:53.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e
IOC database
- Type
- hash_sha256
- Value
03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e
hash_sha1
1bea31adb7a91754124852e0ab9bea26130cd23d
VT 4 / 75
IOC database
- Type
- hash_sha1
- Value
1bea31adb7a91754124852e0ab9bea26130cd23d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Nzfl |
Details From VirusTotal
Basic Properties
| MD5 | ff09a9ca805ba956003ab17c08659d3f |
| SHA-1 | 1bea31adb7a91754124852e0ab9bea26130cd23d |
| SHA-256 | 03e7836cff797e9b13b77403733f04f5c1c0e195c395b67069bb5b7efd3a274e |
| VHash | 67633b6edbaa6cc7ef9931520b36d235 |
| SSDEEP | 196608:FIGWWUgXPIHJSp1OEqlFPSwKpg/hZ1r4d8Iqk:FI/cIH8fm3KpmhZ9jI1 |
| TLSH | T188961207667E0A24EC0FE9F2C415B73359AD3392E0D6706B51B82DC06DB36E4139FA69 |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 8.8 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
q67sr.exepulse.jar.github-Course23sz.zip
hash_md5
ff09a9ca805ba956003ab17c08659d3f
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ff09a9ca805ba956003ab17c08659d3f
IOC database
- Type
- hash_md5
- Value
ff09a9ca805ba956003ab17c08659d3f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ff09a9ca805ba956003ab17c08659d3f
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 9231196 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:53.
Remediations (10)
-
web:docs.github.com
This will help you assess the risk and determine the best course of action for remediation . Determine the secret type and its provider. For example, is the secret a GitHub personal access token (PAT), an OpenAI API key, an SSH private key? Locate the repository, file and line that contains the leaked secret. Identify the secret owner.
-
web:gbhackers.com
A large-scale malware distribution campaign utilizing GitHub repositories has been uncovered, weaponized over 10,000 repositories.
-
web:github.com
Structured remediation procedures for CVEs identified across home-lab and enterprise environments - Pulse · AdemolaTech23/ Remediation -Runbook-LAB
-
web:github.com
Claude skill to automate discovery and remediation of GH advanced security vulns - Pulse · SecurityMindedSolutions/claude-github-vuln- remediation -skill
-
web:labs.cloudsecurityalliance.org
Key Takeaways Security researchers at Pillar Security disclosed an active supply-chain campaign, dubbed Deadbugz, that distributes a malicious Model Context Protocol (MCP) server through unsolicited GitHub pull requests and hides its payload behind a runtime call counter rather than embedding it in the code or configuration a reviewer would inspect [1]. The server behaves as an ordinary text ...
-
web:pulsevisuals.pro
Pulse создан для тех, кто ценит стиль, удобство и максимальную производительность. Плавный геймплей, продуманный интерфейс и стабильная работа дают вам реальное превосходство в игре.
-
web:thecybersecguru.com
Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it
-
web:www.joeyverlinden.com
Please see the following new blogpost: Endpoint Analysis Proactive Remediation Community Repository - Joey Verlinden In this blog post I'll share my most used Proactive remediations with you.
-
web:www.timestored.com
On linux/mac right click the .jar file, goto properties and set the checkbox "allow executing file as program". Or use sudo chmod +x pulse.jar Try double clicking on the jar file. Its not working from the GUI let's try the command line: Make sure you have Java installed on your system. Check this by typing java -version into the command terminal.
-
web:ziadsaleemi.com
Step-by-step remediation guide for purging malicious IDE extension artifacts and hardening local developer workstations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.