
Fake Activation Tool Hides From Sandboxes, Not Scanners
A PowerShell dropper disguised as the popular Microsoft Activation Scripts installer flags 14 of 76 antivirus engines yet returns clean from sandbox detonation, a split consistent with deliberate dormancy. It surfaces alongside a freshly registered domain, masgravr.site, whose wildcard certificate was pre-staged across four sibling TLDs weeks after registration.
A 744-kilobyte PowerShell script circulating under the name of a familiar piracy tool — MAS_AIO.cmd, the all-in-one installer bundled with the open-source Microsoft Activation Scripts project — carries a detection profile that should worry defenders more than its modest flagging count suggests. Fourteen of 76 engines call the file malicious and VirusTotal classifies it hacktool.presenoker/abapplication, yet the lone sandbox that ran it came back clean, zero malicious verdicts out of one.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read