Fake Online Speedtest Application
An analysis of several Windows applications masquerading as legitimate utilities reveals a covert malware operation. These apps, including fake speed testers and AI search tools, install a Node.js runtime and execute obfuscated JavaScript via scheduled tasks. The malware communicates with a command and control server, potentially allowing arbitrary code execution. The operation's sophistication lies in its use of seemingly benign applications as cover for persistent background processes. The malware's capabilities include encoded network communications and the ability to receive and execute remote commands. This technique significantly expands the attack surface, as the malicious component operates independently from the visible application.
AI Analysis
Technical Summary
This threat involves a malware campaign leveraging fake Windows applications that masquerade as legitimate utilities such as online speed test tools and AI search applications. These deceptive applications install a Node.js runtime environment on the victim's machine and execute obfuscated JavaScript code via scheduled tasks, enabling persistent and covert execution. The malware establishes communication with a command and control (C2) server using encoded network protocols, allowing attackers to remotely issue commands and execute arbitrary code on the compromised system. The use of scheduled tasks (T1053.005) ensures persistence by automatically running the malicious payload at predefined intervals without user interaction. The obfuscation of JavaScript payloads (T1027) and encoded network communications (T1573.001) complicate detection and analysis. Additionally, the malware collects system information (T1082), performs credential dumping or reconnaissance (T1057), and can download and execute additional payloads (T1105), expanding its capabilities and attack surface. The campaign's sophistication lies in its ability to operate independently from the visible fake applications, making it difficult for users and traditional security tools to detect malicious activity. This technique effectively hides the malware's presence under the guise of benign utilities, increasing the likelihood of infection and persistence on targeted systems.
Potential Impact
For European organizations, this threat poses significant risks including unauthorized remote code execution, data exfiltration, and potential lateral movement within corporate networks. The stealthy nature of the malware, combined with its persistence mechanisms, can lead to prolonged undetected compromises, increasing the risk of intellectual property theft, disruption of business operations, and exposure of sensitive customer or employee data. Organizations relying on Windows environments are particularly vulnerable, especially if users download utilities from untrusted sources or lack adequate endpoint protection. The encoded communications with C2 servers may bypass traditional network monitoring, complicating incident detection and response. Furthermore, the ability to execute arbitrary commands remotely can facilitate deployment of ransomware or other destructive payloads, amplifying potential operational and financial impacts.
Mitigation Recommendations
European organizations should implement a multi-layered defense strategy tailored to this threat. First, enforce strict application whitelisting policies to prevent execution of unauthorized software, especially utilities downloaded from unofficial sources. Employ endpoint detection and response (EDR) solutions capable of detecting anomalous scheduled tasks and Node.js runtime executions. Monitor for creation and execution of obfuscated JavaScript files and unusual network traffic patterns indicative of encoded communications with external servers. Regularly audit scheduled tasks and remove any that are suspicious or unauthorized. Network segmentation can limit lateral movement if a system is compromised. User awareness training should emphasize risks of downloading and running unverified applications. Additionally, implement strict egress filtering and DNS monitoring to detect and block communications with known or suspicious C2 infrastructure. Finally, maintain up-to-date threat intelligence feeds to identify emerging indicators of compromise related to this campaign and apply behavioral analytics to detect deviations from normal system activity.
Affected Countries
Germany, France, United Kingdom, Italy, Spain, Netherlands, Poland
Indicators of Compromise
- hash: 02b0805388d42f522e9e5aa2e239b14e
- hash: 10bd14c9fc9e9f6025c839f8fa2adc04
- hash: 140c9606e6241709cd3e32808adaf37a
- hash: 1f5dda7f77943a5523e32f233639d05f
- hash: 2103c97c65b941bc8ff3b0daa19aae19
- hash: 287de08218ea23f7e795da3caf525bb6
- hash: 296690fcb018a76cbfd5c9a16123a575
- hash: 2c8508dcce097a55dcd90f97b076ad4d
- hash: 3444394fed9c89def4a5272bbb7411ba
- hash: 3721f97ef3caaede98c3185b6c7976a3
- hash: 3dbd10478d2d2b21d11c0e392e3cb751
- hash: 3fcbe3130110107d4c2cdbaac2efe49b
- hash: 45913a32740f343db1e8b1be1d713cfe
- hash: 45e2df8ec79592f70e9ce3b15eebb1f0
- hash: 47b88ea75682acd3cd9a6bb703b64d7b
- hash: 5238ac0d271bb88c2677e16aff56c67b
- hash: 5276789f062e9c58fe0d0fd282f4c8be
- hash: 5323dcab8dc8bd7e3282e75c0357eeab
- hash: 5a05cb352bf5416a999e966b5d550ba3
- hash: 6d67c17cc52fc58b1a87f18476c2acfe
- hash: 711f795a1e9dc4d683e3a73b7b9a858e
- hash: 72da556c53cc45e67e7afebe85b1515a
- hash: 754185f2efbf9a8216652ae65be32e04
- hash: 77b85765b07954ac0ef88757cb87ac85
- hash: 79e46580f09cb99c38fad1c6022d9e99
- hash: 7e1b25ccbbab57ea1f222cc0c2e87a8b
- hash: 7f654b72eac781c23f51d5b1a1692339
- hash: 85e25a777e7b6b9b06d5114345b14352
- hash: 9b6bf30347cadbcc38b5a145c2e54445
- hash: 9caeb82ce8ab736952e40cab08ba4994
- hash: a345b3badf46f4afee953c02727afec3
- hash: a6080636b3177130a42eae7799af4efe
- hash: a8e5ab57ba3c08ac31c11836cad46d44
- hash: a9adc705fb0e2f0e6668038f3baa0003
- hash: ac5b92d5cd1ef266d5fca3d02424f8ca
- hash: ae5d8bca5884117d770c9951815cca14
- hash: b264dc54f1055eb4c1164cf1d05d15db
- hash: b2692128faa0481ff94ed61c73f76a67
- hash: b91775695212ad5b363bd1b66e760314
- hash: c35cb8e4ce9ae9e11509f241d40e99bf
- hash: c7b01fbde712d64d869225543b5f2e32
- hash: c900877156d21f228d8dd555241e75f0
- hash: d4ac35914e8cc307c6e972214b3218c8
- hash: dd66494bba62dbfb7f96fdb1dd8326bf
- hash: e145b47680a8f1f9aa7a7c1cfeb0fd78
- hash: e61b911d99949410adf9a403f6fca53d
- hash: ec632e31ceae95ad3e5e84170bfd4724
- hash: f48e58a8e3b846c7e4823228098073fe
- hash: f6e7b560735df83efa3f10982af991fc
- hash: f75701d37fa7eaa7fabc87e9e6e00c0d
- hash: 000cf2791f6d0702c5427242e05e813b4c5b8ee5
- hash: 01ede2327fcf1f9289af1491a11e0d182445649d
- hash: 07335ab93f0bccf81bc596d502ec0779099f2540
- hash: 0c843c2d6a15bdae7152d11d15f6f3895d830ccd
- hash: 0cda086c7c529a31bbfb59b698d2010eb440e48a
- hash: 100211034eabbcfdbf810c4db696fcd9e0b98b0f
- hash: 1131cbae543d2e6f893d6ef730b27a9bd946c836
- hash: 136ca0a036f86d3a2b9c6d37a258cb00fad76c5d
- hash: 188915e1d8cd942ddae910ef9591fef24b4f2cde
- hash: 1e5c32a74aee5fd1ce1218b99e79d4354b12a8da
- hash: 1ef153573b544bdd64246b2fba7f2dc1b3b51c18
- hash: 21f55a2276429a2a7640a00567cb98f940388435
- hash: 2bc0721c4255e15bcf3bc8ad7329f6e3a2fc0f93
- hash: 4163150b7d8b5be20d00bd01870437e916269af0
- hash: 41f10f35ff524d2f9f3751865bc07e84966be27d
- hash: 435fe341b9abd6810243425de1ff978aef0edb25
- hash: 45faa96587f21129eb873ab44a5494f52f6739ba
- hash: 4b7304533c2021219a49637f9b75af67bb9c9795
- hash: 4eb2fd9c4bead4e4b4c53167e6eaa4e3f6f0ffa4
- hash: 61ca26f402efc5f7ac717b6f4960706b20d644eb
- hash: 623abe5af67aca2615592f6c602976ec3997a2b5
- hash: 63a35c1f6d0699af9a6ca24e99955ea5585b4072
- hash: 6922ea401def21f8ad31eefe38bc8440bae77d5d
- hash: 6b02f631557673043d2e1487b853c4cabbe8b284
- hash: 72751048f397626483be71c6c856a059674f85ae
- hash: 72d07d178ce032ab8f4257b0571cdaf28cdf3df0
- hash: 8a91094d4da47e2bdcd2136f1757c57bf4bbdbac
- hash: 8abadbb8e5d879bce73af14210dd475ece129d33
- hash: 8ed816f96010cc10109f8bfee5eaa4b35d63da16
- hash: 99641c8990116f54ba7456863548c0ebbbfffd7d
- hash: 9c45525e23593f13a395acc52795f4bfebac7c23
- hash: 9cd4d36b575fc5840c8811b2c01794ac04506586
- hash: a8b2b235e756a0bb719b9f62ad487970ef630b13
- hash: a93907e77340e4aadcc66e1afb9d342789f0cbd1
- hash: adb99bb8bef982572347a924b7796b4fa3e72af2
- hash: ae8f72a8f5663096a2e05493e21445bc414c3c07
- hash: b1d7709f66c3c5384b47c7b59de7ddf64d4afa32
- hash: b966d657e72dcb301d6b95e6f4ce2a5035883930
- hash: c13546d04b934d756743594b4ab8a0ca5932db0f
- hash: c3515216500dadf71a765a565f68d1761569b701
- hash: ca59f3349d96bb4670d67272f5407b1ebe59e8be
- hash: cd080b96555523b09c41b026d4e323b35b1db206
- hash: d4cba44f81c114a38b32ca2b6bd3a7cd2818e547
- hash: db33b2b39ad206a60a54a42912ba5737258d4b19
- hash: dccff7f4e377ab928127cc61c1f29b14b7ccb335
- hash: e5507e8a97d1585ae354cebfc79f8c2d1255d3ae
- hash: e8576fafa6b95ea9f8bef5d34128bcd8b28d292c
- hash: f10743a6ecfcd8ed0c13e276154efb7c8aa79d8e
- hash: f75023f2ffe580de09e265b5b82b820224eae489
- hash: f7fbb4b0623f007dbeb53e4978ac44108bb4ed81
- hash: f8fbd49b46be0940758c9530824b225903f2f050
- hash: 01be1921183b9bf658aed25dbd6e90119bb2741984fc0e7e74789fa32ec0512e
- hash: 035e7dd115afc47704db586a61aa9c189cde7228e752e0491352930f20d97dcc
- hash: 0450783005239eeb1eb07eb1aa9e1228af3d64b9aee9c7d9461a83f6d71ea7e3
- hash: 05d9f4426ad77fcf73a357a4f5ca1d0cf9ceccf44117c1bc829afb79a2f8671b
- hash: 091d3bf2f0f6dc08b23151b5acd7cf53217d1ed2812e507d96dc467d9d3092d6
- hash: 0abd1e39e17fa99366c8f1cc9171730867b6e86f6362b0492a090170f0305e55
- hash: 0b90c3ef5bc8918c334638f2f11100a992fafbca7e16934652b70f3b2579131b
- hash: 0bf92be9bb3989d78ce9f345df190a543eb984cc5479928399b4610d5d94c41f
- hash: 0e024267203ff2c7239bdbb73bc425536ddd8153a4df430e1d95bddb34d2af95
- hash: 10f8df3d2aea28382f829c65a9af2cd869d43eba88c53fa067ec3958ed0181c7
- hash: 113b23c062229aa57dfef68631f85f615e61673024b73cb9c0f5269b712610fa
- hash: 12dfbfaba2271a2a2a30c502afd69bcd9783400914f6f075ba141625ef62dd03
- hash: 12f89e34e4d34be57501387cfd2d1cd6a956cb5b29e90d6dfa7bf18ad46656af
- hash: 131edd182563327dd218f99150e43efa445e919f6d0566a845154afb0a085b61
- hash: 140c34a4a3f9535c06a0b3c99a54870e04c68eca9a463958fb4e2453b40f3c1e
- hash: 14577f1a8d5ea9f5f255b456f0f69fe4e3a1cba82d707de28b3ca25410393c17
- hash: 16e8874d199a578acb10fd16ac60e20d2b2c0b77ffacf7f39a0203b14d94392d
- hash: 1751e9317d71f54b69287948da8ff6ea44de79295e2a8bd35eeb9e5978f47d06
- hash: 1fc4819fcf2522622fd846bf4abcd03ae02adf41366b9911fe7bb30f2a4dc4b7
- hash: 218a3a2e60779c4b4f1c83467f93d7b5c405b9acb799b4b2cdaacb7b26cd48a1
- hash: 2355ee5283fe7171d5d74302eb7f4e371e2e76c52eb3f07ff3a954a854ae8e4e
- hash: 23d6ee179f84167b03196e48c7a951da98ecaba26a7bf2f8e87f5783b8c3c334
- hash: 25575ffd50528952865b2b1df354461148474606c1adc68c0f140e3dcab10362
- hash: 258926957136cd029a4d2d83b299656237c9cc37372191be2b15fc6effa85be7
- hash: 2c2a0f2fe3a596a551155520612fa7d093b5311dfe477da6f0a2d511cfbd5b11
- hash: 2c4930c40225965e6736976d83e989623b9a03cf5c4d9b0f99b5799664371757
- hash: 2c5ffcb73cd1c32937cfe2752c3a4e061dcf394c28a044001bed43bea3312c34
- hash: 2e09e1e2d6a50bdcee23859035d26ae2a198fdc77727eacb291c25875d664267
- hash: 30bd7b22e1a05edd384cc776cbb00bab9e3a043b1c1c410ddda637425a608cea
- hash: 30c18e8abfd75c796c3fd4bdd55f3de72c137ee72cc56f7bc4f78fce10c0e717
- hash: 30d21ea26917366654f606a8577b430cafe03654432cc97598fad30d16157e2c
- hash: 315c2c6654cc4a29597ffc2c5694e38385e67b3f8b149960874a539836c5773d
- hash: 316cd4f5ad1fef6b4ea700ff6fe1589a8ece4a377383033a134733ad7551e17f
- hash: 321502fed2cf378d9f0ca4710a969315487f65476ef3142336d046a8a7f535d5
- hash: 3348ada126068f3adecf9ec9f707e719184fb652b7cba1b700f8f377b841e1d5
- hash: 3697f763980e594c83d708b43c410f753134e83baf33f822bba36133e0b1eafc
- hash: 3731b729ffc4aaa42bacb56e0340e29d3b0cb5d14f287bc281ecb716eba0d8d1
- hash: 3c34ec7e666c853465058b96421c018d93e532350547a90a6f68c7db5414a4b1
- hash: 3c51ca74e721e5e177c5a8495131d7a65ea6733ea8e8875ba3e1ce0270a136b7
- hash: 3cccbe2e524cb458ea48c108e36efabbf36c76cf30c80b64f52acf8b7b113de9
- hash: 3cdee1c90386201df6028ea57378d6bda54fe3d6d5237239c9d919b063bc675c
- hash: 3daf887dc6ff2bd7bb5fdddb0189e7e6f383d06ed01f7dd5ae845098127be897
- hash: 3e3b666102dcb01cdc77dc3d043f4ccac4dd05e98e81712e9292441aa9b83772
- hash: 4358eb448e194f4058677a4e38e269a96c61580f7fad3bb2a34a23ff3121b3be
- hash: 43f09da2df507929ac596ddfbb0f0c2485058a23b7436763887de6e457333244
- hash: 4635ed9c0d6d77513e1d10575e0670f86466ac8aae41620f15cf15e62e280ff1
- hash: 47a359fa4181ad4932934a7d7d41f880c2be25491ae3c27ce59020e58c352820
- hash: 492f9757edba4e58462a4a697c5145ab9fac1571c92482bf9b195a063f3d4fce
- hash: 4967262d1b136bb77be89a2e15c732a9edcc0377b6aaa88a6abecf5a4f8b9215
- hash: 4a298680ae38868fd2dd81f8c90883072e9fa67d7d72ac9feb7095b388b948a8
- hash: 4f89dd3b73438751feab0bf92c5d732db86796375d21c29e9437de2391223a15
- hash: 512735bb19571707ab484cdfdb2cba74f5a8fdd9e415a8ea8ccf5c1f326f9a4e
- hash: 52d234e085c8bf67fa9d338cc5621f17d4ebe166f180896185e5f28c2655c811
- hash: 53e95841106499cf90494d7f90ff6baf71d0d4b3cc6b23a299ab987d3b9dc76e
- hash: 55a33c19b1ba67d94c0700c1e2ce60500ceac4d4b2487d9e5eb603f97dc0c2fd
- hash: 5600dda9f7273f3bbeacb35aaa795e39bf8376cae66b5e4466769f306c6800f9
- hash: 5ca8c9224dcf9e69cf9a5c516e5be8a6fb4456339ce381d69be2877b60cbf444
- hash: 62d6c1e8778d512860dd730b918f33919df960ce97a019a1e3b28ef2c7fd60a4
- hash: 644d560018f1237b3b339019ac7e21b54b94e8b15edbab5d45b7ef82998c7d5c
- hash: 647acbe4e2ddb36ba6868de80d72a7750142239ebe46ff468a99845ec638fc22
- hash: 694fbbb9f7fb7650614808d1499a311777fb93c960e936103836ac8511054105
- hash: 6965a90500789b1d890432a97e8deb83665bbd9cc7755bd4de4c5de9f4e2fcf7
- hash: 6b055fedb913da5ed8b736c5dc1e56a9afe86858b1c46fdb7e8f981d6e5d966f
- hash: 6bade765470e3a42dd2aa72536e6a6d5f5436baf30b64dae6799c4f7acddd1b0
- hash: 6c9cc972f9f39c089c9e893dbca988d11cb811826d3d1e27c854f9723e529503
- hash: 6ea919c991b29ac78d80b9b6080c380a3e53813e1a2b0c3e576763a3ec22ef05
- hash: 70583bb0d6fa6c2a3a3ca38d17f26d4dda3ec7223350750ba5a2e12c16733fd2
- hash: 71273af47ee2792b68320054ebf44d2dfe4cbe7825c0aedc5a9b65abb5744851
- hash: 726a59dd49ec89f53b4eee0bdbe9bd0775ab2dc96aab34a46dcd71655bc62765
- hash: 7291a11b822d5b69413afb1d6569c2b14a243d30c7e2a7c2b0f28e886a77a352
- hash: 7364b8cefd46a8ff918df679066fb8041b98a3e57a09f782ad6f8757fabf56cd
- hash: 75b6ee6184af5c9a19736f211cd2b359bd5bb5aecc79af9ceb859a6e9cdb9a5a
- hash: 7833b0ae1d4daeb7f35577c32a7aa2bb0659fd681fb36c6196f4457003c1e990
- hash: 7cd6564324d767008def4a8d5819c21b577f70f3ab51bc2667b8828f472109ef
- hash: 7fe170dc2ca9f333a177d7d2a5f6fee9e674164e7b46b2c2590c49be1aa9fe05
- hash: 7feb6ac46747af846a2732148148933adcf38e8ef1423750b73bbd9f0382d4e6
- hash: 802fda5435cb7d3121d1b21e3cb721072d1a42991901835187e0dbca60e35edd
- hash: 8033669bb8287a4df5346ee0f5b35a3c4450433f595ab0a2d18ddb232d9988d7
- hash: 82647675445e0d1198639c050880dbea13cc1ba61a18e99ecaa1dd0669f5ac24
- hash: 82c452855e3d41cb1a3396e8e1aed7e26812f127ef31c93a8f375e1acb458ff5
- hash: 8be6cd8cea71c3e4288598f378d67981e2b4464ff5d673e0dd98909a78009bb7
- hash: 8ecd3c8c126be7128bf654456d171284f03e4f212c27e1b33f875b8907a7bc65
- hash: 8f0c62362e93d4252e234da7f3277ec9cf93638002cd7c5065d4624993a828c4
- hash: 8fb8d1df307f58db070eb5aa82a3ef3a41512d2aa73278d574ab32e55123488a
- hash: 8fd4b095fad78130c0b3cdaafa9db0fa523a60b7e837f9934d3855c03504ee47
- hash: 923d6031fa237b5ba80f6dfdf1b9de5d9db297d571c343ed33e8fad9423ccf84
- hash: 92c7cd5e4d0c584d11999d8dbee3deb572aa03dbdfe39087e08ece27f0eed80a
- hash: 93205b3a87348cc2886154b5d30f88711c9e050a671baf927fb727a15f72382d
- hash: 93e0cb7c8dcc90e1453ed239fb164f1edf16f980fecc48a85790ec1803dad35d
- hash: 94dc4138bfabf6a3e7cefffc5f5062fe0ac31384bae4ad78f27557ddb29f6eae
- hash: 94fbb9cc3af0d9ec25d415e35ec65491d6182e452265c854e125cfd94227a53d
- hash: 97cb7a45f72172cc01a12891ce04202de14fcc7cc878451778ab19b3cdda6316
- hash: 99e80590240a4047aa12ae7f640389b20f9482bc7082b3a325f1ebefb07df567
- hash: 9a77a653ed5c2ec0f9c00019ef6a5cf6153335fcb636c5e56edc3ccd7ad12cd2
- hash: 9c9fec959f42e8c9a99fe539614abd85171ceac422eb3db82b027a6fee433548
- hash: 9dd04ddce819aebad34e681b24ca934d06918fe45b299762e984a2a831a53644
- hash: 9f5538afb90dfb0eac126808868a65403a09758b63e3688ef17df1de27782813
- hash: 9f948215b9ee7e7496ce3bc9e46fda56b50cc8905b88535225c7651007f660d5
- hash: 9fb1dc56a042e6eca786f3aaa7b21d148dfb8276f6cc2cdb867408b20117f547
- hash: a0dae9b551026295575dcf4b1f668069b8fe8119458e792e8293299a74e79436
- hash: a16cbf9ab535d4ad628b583ec3e026799f38bb50b98c495333302f7b804390ea
- hash: a16ecfcf5e6d7742f0e642309c3a0bf84eaf21962e663ce728f44c93ee70a28e
- hash: a22c7cfd0dc9465a81bd6f99ad8ae0d2074e6f61ab9114582ca9a1da9960c586
- hash: a3ad384b05d824e2097cf36e2182155cd67c88637d0ee908c59241ea4e98a32a
- hash: a5187cbb42b0e0dfb747c8fe86638dc68be9915ec112f7f6f72c8f3735489c76
- hash: a609d6386414bf8241a084cd3bf819c06790e8b76f6b2f4ba792c3109fa9b47b
- hash: a7153585ae5ca228419ed4e6293ec910b8ca98218e278479e3fcc67101e11ffc
- hash: a7fbbb0393e36bc70b6eafb967a3b11a65c442090da1840364886b984784135c
- hash: a946a59d49e946a1eebfcf6ff2e8e46515380cd4668f60b265cb1a891ee0bd68
- hash: ab4cd54823a162838a87317d3d368d32c0ea623128252ee05a0c63318f55cec1
- hash: b09fd02e58afd99f7ee8b00c604319d5e83cfa63819b6dd56568fbf4dbce528a
- hash: b2665f90c1c54dcc77aa3cc62acde7f92101b570159a13dc7c5b774665a9bee6
- hash: b32216f83e73459209cfc504f18b17033a8f8c020ea1932fdcdb77b2e5a88f50
- hash: b6428ce4bf46091df0f96777ab5a2c187ddf4d788421d8b498a9d390b93bc2de
- hash: b78183db84847c13a4158c0b8c54326876b350924410912fe0dc9c25c15f3eca
- hash: b850b218d5cc4cc9c1006399c26cc5ca3f9e2da3a70296fceb6760d1f0dcdf90
- hash: bfac5488c805b5e87a130ce74b7961832da3d55f51e9e2d0d00d1cea1019c309
- hash: c36db02b3f57189d504a7e688befa31a379b307c663a54c799f2bedd0dc471a7
- hash: c391b1e00a8fcc120605a6e0c4e26c5ec9624b8e194460d34ae0d26efd147847
- hash: c8041e1b76b14406ddb4cbbc17deba3e28a7780cc86dc913c8dc727398b79bf0
- hash: c837eb288129072ed78885a4cb4f2de307ac37a3644a57c893b6a545ff3ddf70
- hash: c99b4cd3655ec4a5a7e49be77a90ce1fb8286f5ed08ad4d20c8c2ab306833f10
- hash: cac499fe09d2640e376c6e6f45d5d287c75faf94d8ba26290016a815a8b4c5b4
- hash: cb680abe9bbfe955721672528c76959d34d600b4f2c624ebf4a75266c80bab87
- hash: cb69835db39dd9babde615340860d599e29d79ffa78516907e96df3413315aa7
- hash: cda23f0134582b73f5de3dc85a2fd5ab8fc9413296f7956c32142f55f1789cf7
- hash: d4bb1e5a4ec89039b6277a102d6d809ac873de4873952880acca1edd29d5e0c0
- hash: d62867ec081a35c719270d76094c043269fdbf2d27bac5ec4e209e8115dde14a
- hash: d67662432658d50fd2da61dded00a4936ad516ddd83477b63fac0601e9e98246
- hash: d70bc73a61252d5d9fde5593670fa790e4e9611838fd6c74f2b9cab97a5cea0f
- hash: d792bc4896854d30b1ea4b2120ec39c4987b4d63802ee0775314f269f138e7f7
- hash: d799cc1713932e9748ec9d293f831d150e1e345c0e58279cd7c3e49c35e667be
- hash: d9a0d3f05ed8efd475f7b76ca3d4ad7d136b274979d2a0abb6ca26d1a2e98512
- hash: dab25bf8e58dd4091fc7496566f5e1374e6bf069c29a61532181a77632e42754
- hash: db0d90d825db484a146ebc43408c8e722b676616c32d84684bc94ddc8b92e893
- hash: db62ac71ac17a2f8e3d19b4f093ff1226d5de7fa323dd4564fb0dbb37ae8a364
- hash: dee105814d284d8aae6a5190e57f51248efe88a9a7a0ab7f935dfaf7d8d3a387
- hash: dfa5785c13a739fb2fae72f405984eef89dc7bf3dd94137692e96826113d51e0
- hash: dfbaec29a20ff7b629d3d33ebb3fd81d2da2c34bb88b4d51c5641f8beb53ce86
- hash: e0a88e5b0b7dd73919257a097b8ca5f1aba5f4a33ff87c19441c3944aa301d60
- hash: e10d4c6a76a56f0a7be5692ea5d1fc44921543d9bc2e82b46a5e65b1196bc980
- hash: e18e59723949ad0a2791e95d4c0ffd7657929e8dc6a0d718598b3aec962f73c2
- hash: e1ef48f5585aef84a0fe193233faa0f46754ae4aed883d1c6aa151d4ffa086ba
- hash: e303900f44f3ba0de6acbdbeba111876b61e512e04cefc92e8e091f69033698a
- hash: e340e41da2779a714c2c0590955ade6dc35b3c9246bde5cca8e1cab1b937593c
- hash: e3cb5e8f623e45088779c90514615d35ad0a3970d49483bcba2917129c8a20bf
- hash: e45f3ac28e2f44cb270210071d60c43b4b55d9249a1e8f9433570795ffec306c
- hash: e60c139bc8b26579496520ccabcf0804d7373b44434d280132b1ebe1e14282a2
- hash: e8c8f6d44559e640cf8db689b32be1cf945658fdde06ba39582e298de1b8f14e
- hash: ea3ffa6c44d5989ece7066422db9d1d821f7aa2efbce317b87ca719b848e6fc6
- hash: ef1b0bbf13ad0851f6f8e5b380288df45f7082d777cf6ea85a2aae281c23803c
- hash: ef4b57bad0d28a65333691e1c27787690d58516a79f9cf2fbe840d69401a1932
- hash: ef521217cefa4037b28621b04ad6f9415cc8fadf420cc78d585208d71faed08a
- hash: ef9621f7fe04fd053e58af7d5863780defd1d2948c131d7df3f76bdb46932688
- hash: efebcb7aba4880380e5c11cdbb109b86aeeb9395463c4e836332b1ed4f8883df
- hash: f4cf5c328bc2c1d2f83676b61a91ed63d536b2ad9cf26707e7ab4a4d25b56c2d
- hash: f52c2c693964f6868bc33d87a97ebecee19b80bc83a1f629193d873127d480c6
- hash: f66a3f181471cca8af12d5a4a890ed3c1c1cbaa41ba3cf2fb765e212ceb391e5
- hash: f7c661fd51350616925c7c11f2eaa5ca953387d906b07d7aa3d44e1487970b95
- hash: f8107237485783f2c88df745e0d7b2ab4471ed794704ad6754f4c2b5c40c2dcc
- hash: f81b533757f4603f2eae935b8b9f466b2c2e3563f44bd40711afbf8980f45eb2
- hash: fb3e788dd80a3ad92d4a5e6feb551b11b73e7c7a2af0f0d72f18eb3f5261aff8
- hash: fcbbea20d65b099759b510dd706ddea71870063b33005902e5dad0fbf07b65d7
- hash: fccf2c72054e9aa8e5a134854e573b23316a6622631f818695d9c0eb3ca3f1a7
- hash: fd02449fd3b318196777a7c72cc642906c5b1c5a70d261aa06ac810285a7fc7d
- hash: fe320d6ab854bacf07013b023cc2ebb4276529d27222b13d63993b84ab311fb9
- hash: fe8d1c45540e64f4b8cc73d9f6ba3f08f3ec8da5ebf6ccaea470fb2122dff275
- hash: 07cd926cacea30be011995815cfac2ca
- hash: 20acdf3519635a75fce5dff425f64166
- hash: 7feff78eaa5bc4b6986c7077b4c0bb82
- hash: 8139f622af19e46bacef44a04890afac
- hash: fbb57b33b603409a00479cc40a7a88a4
- url: https://cloud.appusagestats.com
- domain: onlinespeedtestservice.com
- domain: cloud.appusagestats.com
Fake Online Speedtest Application
Description
An analysis of several Windows applications masquerading as legitimate utilities reveals a covert malware operation. These apps, including fake speed testers and AI search tools, install a Node.js runtime and execute obfuscated JavaScript via scheduled tasks. The malware communicates with a command and control server, potentially allowing arbitrary code execution. The operation's sophistication lies in its use of seemingly benign applications as cover for persistent background processes. The malware's capabilities include encoded network communications and the ability to receive and execute remote commands. This technique significantly expands the attack surface, as the malicious component operates independently from the visible application.
AI-Powered Analysis
Technical Analysis
This threat involves a malware campaign leveraging fake Windows applications that masquerade as legitimate utilities such as online speed test tools and AI search applications. These deceptive applications install a Node.js runtime environment on the victim's machine and execute obfuscated JavaScript code via scheduled tasks, enabling persistent and covert execution. The malware establishes communication with a command and control (C2) server using encoded network protocols, allowing attackers to remotely issue commands and execute arbitrary code on the compromised system. The use of scheduled tasks (T1053.005) ensures persistence by automatically running the malicious payload at predefined intervals without user interaction. The obfuscation of JavaScript payloads (T1027) and encoded network communications (T1573.001) complicate detection and analysis. Additionally, the malware collects system information (T1082), performs credential dumping or reconnaissance (T1057), and can download and execute additional payloads (T1105), expanding its capabilities and attack surface. The campaign's sophistication lies in its ability to operate independently from the visible fake applications, making it difficult for users and traditional security tools to detect malicious activity. This technique effectively hides the malware's presence under the guise of benign utilities, increasing the likelihood of infection and persistence on targeted systems.
Potential Impact
For European organizations, this threat poses significant risks including unauthorized remote code execution, data exfiltration, and potential lateral movement within corporate networks. The stealthy nature of the malware, combined with its persistence mechanisms, can lead to prolonged undetected compromises, increasing the risk of intellectual property theft, disruption of business operations, and exposure of sensitive customer or employee data. Organizations relying on Windows environments are particularly vulnerable, especially if users download utilities from untrusted sources or lack adequate endpoint protection. The encoded communications with C2 servers may bypass traditional network monitoring, complicating incident detection and response. Furthermore, the ability to execute arbitrary commands remotely can facilitate deployment of ransomware or other destructive payloads, amplifying potential operational and financial impacts.
Mitigation Recommendations
European organizations should implement a multi-layered defense strategy tailored to this threat. First, enforce strict application whitelisting policies to prevent execution of unauthorized software, especially utilities downloaded from unofficial sources. Employ endpoint detection and response (EDR) solutions capable of detecting anomalous scheduled tasks and Node.js runtime executions. Monitor for creation and execution of obfuscated JavaScript files and unusual network traffic patterns indicative of encoded communications with external servers. Regularly audit scheduled tasks and remove any that are suspicious or unauthorized. Network segmentation can limit lateral movement if a system is compromised. User awareness training should emphasize risks of downloading and running unverified applications. Additionally, implement strict egress filtering and DNS monitoring to detect and block communications with known or suspicious C2 infrastructure. Finally, maintain up-to-date threat intelligence feeds to identify emerging indicators of compromise related to this campaign and apply behavioral analytics to detect deviations from normal system activity.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://security5magics.blogspot.com/2025/09/fake-online-speedtest-application.html"]
- Adversary
- null
- Pulse Id
- 68d50967331055dd8308adfd
- Threat Score
- null
Indicators of Compromise
Hash
Value | Description | Copy |
---|---|---|
hash02b0805388d42f522e9e5aa2e239b14e | — | |
hash10bd14c9fc9e9f6025c839f8fa2adc04 | — | |
hash140c9606e6241709cd3e32808adaf37a | — | |
hash1f5dda7f77943a5523e32f233639d05f | — | |
hash2103c97c65b941bc8ff3b0daa19aae19 | — | |
hash287de08218ea23f7e795da3caf525bb6 | — | |
hash296690fcb018a76cbfd5c9a16123a575 | — | |
hash2c8508dcce097a55dcd90f97b076ad4d | — | |
hash3444394fed9c89def4a5272bbb7411ba | — | |
hash3721f97ef3caaede98c3185b6c7976a3 | — | |
hash3dbd10478d2d2b21d11c0e392e3cb751 | — | |
hash3fcbe3130110107d4c2cdbaac2efe49b | — | |
hash45913a32740f343db1e8b1be1d713cfe | — | |
hash45e2df8ec79592f70e9ce3b15eebb1f0 | — | |
hash47b88ea75682acd3cd9a6bb703b64d7b | — | |
hash5238ac0d271bb88c2677e16aff56c67b | — | |
hash5276789f062e9c58fe0d0fd282f4c8be | — | |
hash5323dcab8dc8bd7e3282e75c0357eeab | — | |
hash5a05cb352bf5416a999e966b5d550ba3 | — | |
hash6d67c17cc52fc58b1a87f18476c2acfe | — | |
hash711f795a1e9dc4d683e3a73b7b9a858e | — | |
hash72da556c53cc45e67e7afebe85b1515a | — | |
hash754185f2efbf9a8216652ae65be32e04 | — | |
hash77b85765b07954ac0ef88757cb87ac85 | — | |
hash79e46580f09cb99c38fad1c6022d9e99 | — | |
hash7e1b25ccbbab57ea1f222cc0c2e87a8b | — | |
hash7f654b72eac781c23f51d5b1a1692339 | — | |
hash85e25a777e7b6b9b06d5114345b14352 | — | |
hash9b6bf30347cadbcc38b5a145c2e54445 | — | |
hash9caeb82ce8ab736952e40cab08ba4994 | — | |
hasha345b3badf46f4afee953c02727afec3 | — | |
hasha6080636b3177130a42eae7799af4efe | — | |
hasha8e5ab57ba3c08ac31c11836cad46d44 | — | |
hasha9adc705fb0e2f0e6668038f3baa0003 | — | |
hashac5b92d5cd1ef266d5fca3d02424f8ca | — | |
hashae5d8bca5884117d770c9951815cca14 | — | |
hashb264dc54f1055eb4c1164cf1d05d15db | — | |
hashb2692128faa0481ff94ed61c73f76a67 | — | |
hashb91775695212ad5b363bd1b66e760314 | — | |
hashc35cb8e4ce9ae9e11509f241d40e99bf | — | |
hashc7b01fbde712d64d869225543b5f2e32 | — | |
hashc900877156d21f228d8dd555241e75f0 | — | |
hashd4ac35914e8cc307c6e972214b3218c8 | — | |
hashdd66494bba62dbfb7f96fdb1dd8326bf | — | |
hashe145b47680a8f1f9aa7a7c1cfeb0fd78 | — | |
hashe61b911d99949410adf9a403f6fca53d | — | |
hashec632e31ceae95ad3e5e84170bfd4724 | — | |
hashf48e58a8e3b846c7e4823228098073fe | — | |
hashf6e7b560735df83efa3f10982af991fc | — | |
hashf75701d37fa7eaa7fabc87e9e6e00c0d | — | |
hash000cf2791f6d0702c5427242e05e813b4c5b8ee5 | — | |
hash01ede2327fcf1f9289af1491a11e0d182445649d | — | |
hash07335ab93f0bccf81bc596d502ec0779099f2540 | — | |
hash0c843c2d6a15bdae7152d11d15f6f3895d830ccd | — | |
hash0cda086c7c529a31bbfb59b698d2010eb440e48a | — | |
hash100211034eabbcfdbf810c4db696fcd9e0b98b0f | — | |
hash1131cbae543d2e6f893d6ef730b27a9bd946c836 | — | |
hash136ca0a036f86d3a2b9c6d37a258cb00fad76c5d | — | |
hash188915e1d8cd942ddae910ef9591fef24b4f2cde | — | |
hash1e5c32a74aee5fd1ce1218b99e79d4354b12a8da | — | |
hash1ef153573b544bdd64246b2fba7f2dc1b3b51c18 | — | |
hash21f55a2276429a2a7640a00567cb98f940388435 | — | |
hash2bc0721c4255e15bcf3bc8ad7329f6e3a2fc0f93 | — | |
hash4163150b7d8b5be20d00bd01870437e916269af0 | — | |
hash41f10f35ff524d2f9f3751865bc07e84966be27d | — | |
hash435fe341b9abd6810243425de1ff978aef0edb25 | — | |
hash45faa96587f21129eb873ab44a5494f52f6739ba | — | |
hash4b7304533c2021219a49637f9b75af67bb9c9795 | — | |
hash4eb2fd9c4bead4e4b4c53167e6eaa4e3f6f0ffa4 | — | |
hash61ca26f402efc5f7ac717b6f4960706b20d644eb | — | |
hash623abe5af67aca2615592f6c602976ec3997a2b5 | — | |
hash63a35c1f6d0699af9a6ca24e99955ea5585b4072 | — | |
hash6922ea401def21f8ad31eefe38bc8440bae77d5d | — | |
hash6b02f631557673043d2e1487b853c4cabbe8b284 | — | |
hash72751048f397626483be71c6c856a059674f85ae | — | |
hash72d07d178ce032ab8f4257b0571cdaf28cdf3df0 | — | |
hash8a91094d4da47e2bdcd2136f1757c57bf4bbdbac | — | |
hash8abadbb8e5d879bce73af14210dd475ece129d33 | — | |
hash8ed816f96010cc10109f8bfee5eaa4b35d63da16 | — | |
hash99641c8990116f54ba7456863548c0ebbbfffd7d | — | |
hash9c45525e23593f13a395acc52795f4bfebac7c23 | — | |
hash9cd4d36b575fc5840c8811b2c01794ac04506586 | — | |
hasha8b2b235e756a0bb719b9f62ad487970ef630b13 | — | |
hasha93907e77340e4aadcc66e1afb9d342789f0cbd1 | — | |
hashadb99bb8bef982572347a924b7796b4fa3e72af2 | — | |
hashae8f72a8f5663096a2e05493e21445bc414c3c07 | — | |
hashb1d7709f66c3c5384b47c7b59de7ddf64d4afa32 | — | |
hashb966d657e72dcb301d6b95e6f4ce2a5035883930 | — | |
hashc13546d04b934d756743594b4ab8a0ca5932db0f | — | |
hashc3515216500dadf71a765a565f68d1761569b701 | — | |
hashca59f3349d96bb4670d67272f5407b1ebe59e8be | — | |
hashcd080b96555523b09c41b026d4e323b35b1db206 | — | |
hashd4cba44f81c114a38b32ca2b6bd3a7cd2818e547 | — | |
hashdb33b2b39ad206a60a54a42912ba5737258d4b19 | — | |
hashdccff7f4e377ab928127cc61c1f29b14b7ccb335 | — | |
hashe5507e8a97d1585ae354cebfc79f8c2d1255d3ae | — | |
hashe8576fafa6b95ea9f8bef5d34128bcd8b28d292c | — | |
hashf10743a6ecfcd8ed0c13e276154efb7c8aa79d8e | — | |
hashf75023f2ffe580de09e265b5b82b820224eae489 | — | |
hashf7fbb4b0623f007dbeb53e4978ac44108bb4ed81 | — | |
hashf8fbd49b46be0940758c9530824b225903f2f050 | — | |
hash01be1921183b9bf658aed25dbd6e90119bb2741984fc0e7e74789fa32ec0512e | — | |
hash035e7dd115afc47704db586a61aa9c189cde7228e752e0491352930f20d97dcc | — | |
hash0450783005239eeb1eb07eb1aa9e1228af3d64b9aee9c7d9461a83f6d71ea7e3 | — | |
hash05d9f4426ad77fcf73a357a4f5ca1d0cf9ceccf44117c1bc829afb79a2f8671b | — | |
hash091d3bf2f0f6dc08b23151b5acd7cf53217d1ed2812e507d96dc467d9d3092d6 | — | |
hash0abd1e39e17fa99366c8f1cc9171730867b6e86f6362b0492a090170f0305e55 | — | |
hash0b90c3ef5bc8918c334638f2f11100a992fafbca7e16934652b70f3b2579131b | — | |
hash0bf92be9bb3989d78ce9f345df190a543eb984cc5479928399b4610d5d94c41f | — | |
hash0e024267203ff2c7239bdbb73bc425536ddd8153a4df430e1d95bddb34d2af95 | — | |
hash10f8df3d2aea28382f829c65a9af2cd869d43eba88c53fa067ec3958ed0181c7 | — | |
hash113b23c062229aa57dfef68631f85f615e61673024b73cb9c0f5269b712610fa | — | |
hash12dfbfaba2271a2a2a30c502afd69bcd9783400914f6f075ba141625ef62dd03 | — | |
hash12f89e34e4d34be57501387cfd2d1cd6a956cb5b29e90d6dfa7bf18ad46656af | — | |
hash131edd182563327dd218f99150e43efa445e919f6d0566a845154afb0a085b61 | — | |
hash140c34a4a3f9535c06a0b3c99a54870e04c68eca9a463958fb4e2453b40f3c1e | — | |
hash14577f1a8d5ea9f5f255b456f0f69fe4e3a1cba82d707de28b3ca25410393c17 | — | |
hash16e8874d199a578acb10fd16ac60e20d2b2c0b77ffacf7f39a0203b14d94392d | — | |
hash1751e9317d71f54b69287948da8ff6ea44de79295e2a8bd35eeb9e5978f47d06 | — | |
hash1fc4819fcf2522622fd846bf4abcd03ae02adf41366b9911fe7bb30f2a4dc4b7 | — | |
hash218a3a2e60779c4b4f1c83467f93d7b5c405b9acb799b4b2cdaacb7b26cd48a1 | — | |
hash2355ee5283fe7171d5d74302eb7f4e371e2e76c52eb3f07ff3a954a854ae8e4e | — | |
hash23d6ee179f84167b03196e48c7a951da98ecaba26a7bf2f8e87f5783b8c3c334 | — | |
hash25575ffd50528952865b2b1df354461148474606c1adc68c0f140e3dcab10362 | — | |
hash258926957136cd029a4d2d83b299656237c9cc37372191be2b15fc6effa85be7 | — | |
hash2c2a0f2fe3a596a551155520612fa7d093b5311dfe477da6f0a2d511cfbd5b11 | — | |
hash2c4930c40225965e6736976d83e989623b9a03cf5c4d9b0f99b5799664371757 | — | |
hash2c5ffcb73cd1c32937cfe2752c3a4e061dcf394c28a044001bed43bea3312c34 | — | |
hash2e09e1e2d6a50bdcee23859035d26ae2a198fdc77727eacb291c25875d664267 | — | |
hash30bd7b22e1a05edd384cc776cbb00bab9e3a043b1c1c410ddda637425a608cea | — | |
hash30c18e8abfd75c796c3fd4bdd55f3de72c137ee72cc56f7bc4f78fce10c0e717 | — | |
hash30d21ea26917366654f606a8577b430cafe03654432cc97598fad30d16157e2c | — | |
hash315c2c6654cc4a29597ffc2c5694e38385e67b3f8b149960874a539836c5773d | — | |
hash316cd4f5ad1fef6b4ea700ff6fe1589a8ece4a377383033a134733ad7551e17f | — | |
hash321502fed2cf378d9f0ca4710a969315487f65476ef3142336d046a8a7f535d5 | — | |
hash3348ada126068f3adecf9ec9f707e719184fb652b7cba1b700f8f377b841e1d5 | — | |
hash3697f763980e594c83d708b43c410f753134e83baf33f822bba36133e0b1eafc | — | |
hash3731b729ffc4aaa42bacb56e0340e29d3b0cb5d14f287bc281ecb716eba0d8d1 | — | |
hash3c34ec7e666c853465058b96421c018d93e532350547a90a6f68c7db5414a4b1 | — | |
hash3c51ca74e721e5e177c5a8495131d7a65ea6733ea8e8875ba3e1ce0270a136b7 | — | |
hash3cccbe2e524cb458ea48c108e36efabbf36c76cf30c80b64f52acf8b7b113de9 | — | |
hash3cdee1c90386201df6028ea57378d6bda54fe3d6d5237239c9d919b063bc675c | — | |
hash3daf887dc6ff2bd7bb5fdddb0189e7e6f383d06ed01f7dd5ae845098127be897 | — | |
hash3e3b666102dcb01cdc77dc3d043f4ccac4dd05e98e81712e9292441aa9b83772 | — | |
hash4358eb448e194f4058677a4e38e269a96c61580f7fad3bb2a34a23ff3121b3be | — | |
hash43f09da2df507929ac596ddfbb0f0c2485058a23b7436763887de6e457333244 | — | |
hash4635ed9c0d6d77513e1d10575e0670f86466ac8aae41620f15cf15e62e280ff1 | — | |
hash47a359fa4181ad4932934a7d7d41f880c2be25491ae3c27ce59020e58c352820 | — | |
hash492f9757edba4e58462a4a697c5145ab9fac1571c92482bf9b195a063f3d4fce | — | |
hash4967262d1b136bb77be89a2e15c732a9edcc0377b6aaa88a6abecf5a4f8b9215 | — | |
hash4a298680ae38868fd2dd81f8c90883072e9fa67d7d72ac9feb7095b388b948a8 | — | |
hash4f89dd3b73438751feab0bf92c5d732db86796375d21c29e9437de2391223a15 | — | |
hash512735bb19571707ab484cdfdb2cba74f5a8fdd9e415a8ea8ccf5c1f326f9a4e | — | |
hash52d234e085c8bf67fa9d338cc5621f17d4ebe166f180896185e5f28c2655c811 | — | |
hash53e95841106499cf90494d7f90ff6baf71d0d4b3cc6b23a299ab987d3b9dc76e | — | |
hash55a33c19b1ba67d94c0700c1e2ce60500ceac4d4b2487d9e5eb603f97dc0c2fd | — | |
hash5600dda9f7273f3bbeacb35aaa795e39bf8376cae66b5e4466769f306c6800f9 | — | |
hash5ca8c9224dcf9e69cf9a5c516e5be8a6fb4456339ce381d69be2877b60cbf444 | — | |
hash62d6c1e8778d512860dd730b918f33919df960ce97a019a1e3b28ef2c7fd60a4 | — | |
hash644d560018f1237b3b339019ac7e21b54b94e8b15edbab5d45b7ef82998c7d5c | — | |
hash647acbe4e2ddb36ba6868de80d72a7750142239ebe46ff468a99845ec638fc22 | — | |
hash694fbbb9f7fb7650614808d1499a311777fb93c960e936103836ac8511054105 | — | |
hash6965a90500789b1d890432a97e8deb83665bbd9cc7755bd4de4c5de9f4e2fcf7 | — | |
hash6b055fedb913da5ed8b736c5dc1e56a9afe86858b1c46fdb7e8f981d6e5d966f | — | |
hash6bade765470e3a42dd2aa72536e6a6d5f5436baf30b64dae6799c4f7acddd1b0 | — | |
hash6c9cc972f9f39c089c9e893dbca988d11cb811826d3d1e27c854f9723e529503 | — | |
hash6ea919c991b29ac78d80b9b6080c380a3e53813e1a2b0c3e576763a3ec22ef05 | — | |
hash70583bb0d6fa6c2a3a3ca38d17f26d4dda3ec7223350750ba5a2e12c16733fd2 | — | |
hash71273af47ee2792b68320054ebf44d2dfe4cbe7825c0aedc5a9b65abb5744851 | — | |
hash726a59dd49ec89f53b4eee0bdbe9bd0775ab2dc96aab34a46dcd71655bc62765 | — | |
hash7291a11b822d5b69413afb1d6569c2b14a243d30c7e2a7c2b0f28e886a77a352 | — | |
hash7364b8cefd46a8ff918df679066fb8041b98a3e57a09f782ad6f8757fabf56cd | — | |
hash75b6ee6184af5c9a19736f211cd2b359bd5bb5aecc79af9ceb859a6e9cdb9a5a | — | |
hash7833b0ae1d4daeb7f35577c32a7aa2bb0659fd681fb36c6196f4457003c1e990 | — | |
hash7cd6564324d767008def4a8d5819c21b577f70f3ab51bc2667b8828f472109ef | — | |
hash7fe170dc2ca9f333a177d7d2a5f6fee9e674164e7b46b2c2590c49be1aa9fe05 | — | |
hash7feb6ac46747af846a2732148148933adcf38e8ef1423750b73bbd9f0382d4e6 | — | |
hash802fda5435cb7d3121d1b21e3cb721072d1a42991901835187e0dbca60e35edd | — | |
hash8033669bb8287a4df5346ee0f5b35a3c4450433f595ab0a2d18ddb232d9988d7 | — | |
hash82647675445e0d1198639c050880dbea13cc1ba61a18e99ecaa1dd0669f5ac24 | — | |
hash82c452855e3d41cb1a3396e8e1aed7e26812f127ef31c93a8f375e1acb458ff5 | — | |
hash8be6cd8cea71c3e4288598f378d67981e2b4464ff5d673e0dd98909a78009bb7 | — | |
hash8ecd3c8c126be7128bf654456d171284f03e4f212c27e1b33f875b8907a7bc65 | — | |
hash8f0c62362e93d4252e234da7f3277ec9cf93638002cd7c5065d4624993a828c4 | — | |
hash8fb8d1df307f58db070eb5aa82a3ef3a41512d2aa73278d574ab32e55123488a | — | |
hash8fd4b095fad78130c0b3cdaafa9db0fa523a60b7e837f9934d3855c03504ee47 | — | |
hash923d6031fa237b5ba80f6dfdf1b9de5d9db297d571c343ed33e8fad9423ccf84 | — | |
hash92c7cd5e4d0c584d11999d8dbee3deb572aa03dbdfe39087e08ece27f0eed80a | — | |
hash93205b3a87348cc2886154b5d30f88711c9e050a671baf927fb727a15f72382d | — | |
hash93e0cb7c8dcc90e1453ed239fb164f1edf16f980fecc48a85790ec1803dad35d | — | |
hash94dc4138bfabf6a3e7cefffc5f5062fe0ac31384bae4ad78f27557ddb29f6eae | — | |
hash94fbb9cc3af0d9ec25d415e35ec65491d6182e452265c854e125cfd94227a53d | — | |
hash97cb7a45f72172cc01a12891ce04202de14fcc7cc878451778ab19b3cdda6316 | — | |
hash99e80590240a4047aa12ae7f640389b20f9482bc7082b3a325f1ebefb07df567 | — | |
hash9a77a653ed5c2ec0f9c00019ef6a5cf6153335fcb636c5e56edc3ccd7ad12cd2 | — | |
hash9c9fec959f42e8c9a99fe539614abd85171ceac422eb3db82b027a6fee433548 | — | |
hash9dd04ddce819aebad34e681b24ca934d06918fe45b299762e984a2a831a53644 | — | |
hash9f5538afb90dfb0eac126808868a65403a09758b63e3688ef17df1de27782813 | — | |
hash9f948215b9ee7e7496ce3bc9e46fda56b50cc8905b88535225c7651007f660d5 | — | |
hash9fb1dc56a042e6eca786f3aaa7b21d148dfb8276f6cc2cdb867408b20117f547 | — | |
hasha0dae9b551026295575dcf4b1f668069b8fe8119458e792e8293299a74e79436 | — | |
hasha16cbf9ab535d4ad628b583ec3e026799f38bb50b98c495333302f7b804390ea | — | |
hasha16ecfcf5e6d7742f0e642309c3a0bf84eaf21962e663ce728f44c93ee70a28e | — | |
hasha22c7cfd0dc9465a81bd6f99ad8ae0d2074e6f61ab9114582ca9a1da9960c586 | — | |
hasha3ad384b05d824e2097cf36e2182155cd67c88637d0ee908c59241ea4e98a32a | — | |
hasha5187cbb42b0e0dfb747c8fe86638dc68be9915ec112f7f6f72c8f3735489c76 | — | |
hasha609d6386414bf8241a084cd3bf819c06790e8b76f6b2f4ba792c3109fa9b47b | — | |
hasha7153585ae5ca228419ed4e6293ec910b8ca98218e278479e3fcc67101e11ffc | — | |
hasha7fbbb0393e36bc70b6eafb967a3b11a65c442090da1840364886b984784135c | — | |
hasha946a59d49e946a1eebfcf6ff2e8e46515380cd4668f60b265cb1a891ee0bd68 | — | |
hashab4cd54823a162838a87317d3d368d32c0ea623128252ee05a0c63318f55cec1 | — | |
hashb09fd02e58afd99f7ee8b00c604319d5e83cfa63819b6dd56568fbf4dbce528a | — | |
hashb2665f90c1c54dcc77aa3cc62acde7f92101b570159a13dc7c5b774665a9bee6 | — | |
hashb32216f83e73459209cfc504f18b17033a8f8c020ea1932fdcdb77b2e5a88f50 | — | |
hashb6428ce4bf46091df0f96777ab5a2c187ddf4d788421d8b498a9d390b93bc2de | — | |
hashb78183db84847c13a4158c0b8c54326876b350924410912fe0dc9c25c15f3eca | — | |
hashb850b218d5cc4cc9c1006399c26cc5ca3f9e2da3a70296fceb6760d1f0dcdf90 | — | |
hashbfac5488c805b5e87a130ce74b7961832da3d55f51e9e2d0d00d1cea1019c309 | — | |
hashc36db02b3f57189d504a7e688befa31a379b307c663a54c799f2bedd0dc471a7 | — | |
hashc391b1e00a8fcc120605a6e0c4e26c5ec9624b8e194460d34ae0d26efd147847 | — | |
hashc8041e1b76b14406ddb4cbbc17deba3e28a7780cc86dc913c8dc727398b79bf0 | — | |
hashc837eb288129072ed78885a4cb4f2de307ac37a3644a57c893b6a545ff3ddf70 | — | |
hashc99b4cd3655ec4a5a7e49be77a90ce1fb8286f5ed08ad4d20c8c2ab306833f10 | — | |
hashcac499fe09d2640e376c6e6f45d5d287c75faf94d8ba26290016a815a8b4c5b4 | — | |
hashcb680abe9bbfe955721672528c76959d34d600b4f2c624ebf4a75266c80bab87 | — | |
hashcb69835db39dd9babde615340860d599e29d79ffa78516907e96df3413315aa7 | — | |
hashcda23f0134582b73f5de3dc85a2fd5ab8fc9413296f7956c32142f55f1789cf7 | — | |
hashd4bb1e5a4ec89039b6277a102d6d809ac873de4873952880acca1edd29d5e0c0 | — | |
hashd62867ec081a35c719270d76094c043269fdbf2d27bac5ec4e209e8115dde14a | — | |
hashd67662432658d50fd2da61dded00a4936ad516ddd83477b63fac0601e9e98246 | — | |
hashd70bc73a61252d5d9fde5593670fa790e4e9611838fd6c74f2b9cab97a5cea0f | — | |
hashd792bc4896854d30b1ea4b2120ec39c4987b4d63802ee0775314f269f138e7f7 | — | |
hashd799cc1713932e9748ec9d293f831d150e1e345c0e58279cd7c3e49c35e667be | — | |
hashd9a0d3f05ed8efd475f7b76ca3d4ad7d136b274979d2a0abb6ca26d1a2e98512 | — | |
hashdab25bf8e58dd4091fc7496566f5e1374e6bf069c29a61532181a77632e42754 | — | |
hashdb0d90d825db484a146ebc43408c8e722b676616c32d84684bc94ddc8b92e893 | — | |
hashdb62ac71ac17a2f8e3d19b4f093ff1226d5de7fa323dd4564fb0dbb37ae8a364 | — | |
hashdee105814d284d8aae6a5190e57f51248efe88a9a7a0ab7f935dfaf7d8d3a387 | — | |
hashdfa5785c13a739fb2fae72f405984eef89dc7bf3dd94137692e96826113d51e0 | — | |
hashdfbaec29a20ff7b629d3d33ebb3fd81d2da2c34bb88b4d51c5641f8beb53ce86 | — | |
hashe0a88e5b0b7dd73919257a097b8ca5f1aba5f4a33ff87c19441c3944aa301d60 | — | |
hashe10d4c6a76a56f0a7be5692ea5d1fc44921543d9bc2e82b46a5e65b1196bc980 | — | |
hashe18e59723949ad0a2791e95d4c0ffd7657929e8dc6a0d718598b3aec962f73c2 | — | |
hashe1ef48f5585aef84a0fe193233faa0f46754ae4aed883d1c6aa151d4ffa086ba | — | |
hashe303900f44f3ba0de6acbdbeba111876b61e512e04cefc92e8e091f69033698a | — | |
hashe340e41da2779a714c2c0590955ade6dc35b3c9246bde5cca8e1cab1b937593c | — | |
hashe3cb5e8f623e45088779c90514615d35ad0a3970d49483bcba2917129c8a20bf | — | |
hashe45f3ac28e2f44cb270210071d60c43b4b55d9249a1e8f9433570795ffec306c | — | |
hashe60c139bc8b26579496520ccabcf0804d7373b44434d280132b1ebe1e14282a2 | — | |
hashe8c8f6d44559e640cf8db689b32be1cf945658fdde06ba39582e298de1b8f14e | — | |
hashea3ffa6c44d5989ece7066422db9d1d821f7aa2efbce317b87ca719b848e6fc6 | — | |
hashef1b0bbf13ad0851f6f8e5b380288df45f7082d777cf6ea85a2aae281c23803c | — | |
hashef4b57bad0d28a65333691e1c27787690d58516a79f9cf2fbe840d69401a1932 | — | |
hashef521217cefa4037b28621b04ad6f9415cc8fadf420cc78d585208d71faed08a | — | |
hashef9621f7fe04fd053e58af7d5863780defd1d2948c131d7df3f76bdb46932688 | — | |
hashefebcb7aba4880380e5c11cdbb109b86aeeb9395463c4e836332b1ed4f8883df | — | |
hashf4cf5c328bc2c1d2f83676b61a91ed63d536b2ad9cf26707e7ab4a4d25b56c2d | — | |
hashf52c2c693964f6868bc33d87a97ebecee19b80bc83a1f629193d873127d480c6 | — | |
hashf66a3f181471cca8af12d5a4a890ed3c1c1cbaa41ba3cf2fb765e212ceb391e5 | — | |
hashf7c661fd51350616925c7c11f2eaa5ca953387d906b07d7aa3d44e1487970b95 | — | |
hashf8107237485783f2c88df745e0d7b2ab4471ed794704ad6754f4c2b5c40c2dcc | — | |
hashf81b533757f4603f2eae935b8b9f466b2c2e3563f44bd40711afbf8980f45eb2 | — | |
hashfb3e788dd80a3ad92d4a5e6feb551b11b73e7c7a2af0f0d72f18eb3f5261aff8 | — | |
hashfcbbea20d65b099759b510dd706ddea71870063b33005902e5dad0fbf07b65d7 | — | |
hashfccf2c72054e9aa8e5a134854e573b23316a6622631f818695d9c0eb3ca3f1a7 | — | |
hashfd02449fd3b318196777a7c72cc642906c5b1c5a70d261aa06ac810285a7fc7d | — | |
hashfe320d6ab854bacf07013b023cc2ebb4276529d27222b13d63993b84ab311fb9 | — | |
hashfe8d1c45540e64f4b8cc73d9f6ba3f08f3ec8da5ebf6ccaea470fb2122dff275 | — | |
hash07cd926cacea30be011995815cfac2ca | — | |
hash20acdf3519635a75fce5dff425f64166 | — | |
hash7feff78eaa5bc4b6986c7077b4c0bb82 | — | |
hash8139f622af19e46bacef44a04890afac | — | |
hashfbb57b33b603409a00479cc40a7a88a4 | — |
Url
Value | Description | Copy |
---|---|---|
urlhttps://cloud.appusagestats.com | — |
Domain
Value | Description | Copy |
---|---|---|
domainonlinespeedtestservice.com | — | |
domaincloud.appusagestats.com | — |
Threat ID: 68d5516523f14e593ee37144
Added to database: 9/25/2025, 2:27:49 PM
Last enriched: 9/25/2025, 2:30:10 PM
Last updated: 10/1/2025, 1:24:12 AM
Views: 13
Related Threats
Threat Actors Leverage SEO Poisoning and Malicious Ads to Distribute Backdoored Microsoft Teams Installers
MediumRhadamanthys 0.9.x - walk through the updates
MediumGhostSocks: From Initial Access to Residential Proxy
MediumXiebroC2 Identified in MS-SQL Server Attack Cases
MediumFlipSwitch: a Novel Syscall Hooking Technique
MediumActions
Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.