FILEMembers
FILE

Fake Activation Tool Hides From Sandboxes, Not Scanners

A PowerShell dropper disguised as the popular Microsoft Activation Scripts installer flags 14 of 76 antivirus engines yet returns clean from sandbox detonation, a split consistent with deliberate dormancy. It surfaces alongside a freshly registered domain, masgravr.site, whose wildcard certificate was pre-staged across four sibling TLDs weeks after registration.

Aug 15, 2026, 14:31 (UTC+9)Last seenAug 15, 2026Severity89ByCTX TeamActorTA505Hive0065IOC5MITRE16

A 744-kilobyte PowerShell script circulating under the name of a familiar piracy tool — MAS_AIO.cmd, the all-in-one installer bundled with the open-source Microsoft Activation Scripts project — carries a detection profile that should worry defenders more than its modest flagging count suggests. Fourteen of 76 engines call the file malicious and VirusTotal classifies it hacktool.presenoker/abapplication, yet the lone sandbox that ran it came back clean, zero malicious verdicts out of one.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence