
Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick
A file cluster tagged with the TA505/rockloader label turns out, on close inspection, to be a pirated 'Microsoft Activation Scripts' KMS/Office activator toolkit. Two of its components independently trigger the same base64-decode-and-execute YARA rule despite being different file types, while two others share a suspicious .win-TLD DNS callback.
A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read