Fantasy Hub: Another Russian Based RAT as Malware-as-a-Service
Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected.
AI Analysis
Technical Summary
Fantasy Hub is an Android-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) subscription model on Russian-language channels. This RAT provides attackers with extensive control over infected devices, including the ability to exfiltrate SMS messages, steal contacts and call logs, and bulk download images and videos. It also intercepts, replies to, and deletes incoming notifications, which can be used to manipulate victim communications stealthily. The malware employs social engineering tactics by creating fake Google Play Store pages to trick users into installing the RAT, thereby evading traditional detection mechanisms. A key focus of Fantasy Hub is targeting financial institutions by deploying fake windows designed to capture banking credentials, enabling financial fraud. The MaaS offering includes detailed seller documentation, instructional videos, and a bot-driven subscription system, making the malware accessible even to attackers with limited technical skills. Although no confirmed exploits in the wild have been documented, the combination of advanced espionage features and ease of deployment presents a significant threat. The RAT’s capabilities allow attackers to compromise confidentiality, integrity, and availability of user data on Android devices, particularly those used for sensitive financial transactions.
Potential Impact
For European organizations, especially financial institutions, Fantasy Hub represents a significant threat to the confidentiality and integrity of sensitive data. The malware’s ability to steal banking credentials and intercept communications can lead to financial fraud, identity theft, and unauthorized access to corporate networks. The exfiltration of SMS, contacts, and call logs can also facilitate broader espionage campaigns and social engineering attacks. Given the widespread use of Android devices across Europe, including in corporate environments, the potential attack surface is large. The stealth features, such as notification interception and fake app pages, increase the likelihood of successful infections and prolonged undetected presence on devices. This can undermine trust in mobile banking applications and disrupt normal business operations. Additionally, the MaaS model lowers the barrier for entry, potentially increasing the volume of attacks originating from less skilled threat actors.
Mitigation Recommendations
European organizations should implement multi-layered mobile security strategies focused on detection and prevention of RAT infections. Specific measures include deploying mobile threat defense (MTD) solutions capable of detecting fake app stores and suspicious app behavior. User education campaigns should emphasize the risks of installing apps from unofficial sources and recognizing phishing attempts involving fake Google Play pages. Financial institutions should enforce multi-factor authentication (MFA) for mobile banking apps to reduce the impact of credential theft. Network-level protections such as DNS filtering and blocking known malicious domains associated with Fantasy Hub can limit command and control communications. Regular monitoring of mobile device logs for unusual notification activity or unauthorized access attempts can aid early detection. Incident response plans should include procedures for isolating infected devices and conducting forensic analysis. Collaboration with threat intelligence providers to stay updated on emerging indicators of compromise (IOCs) related to Fantasy Hub is also recommended.
Affected Countries
Germany, France, United Kingdom, Italy, Spain, Netherlands
Indicators of Compromise
- hash: 00ba72f40855e703c318cabb441af736
- hash: 00ef76ea4e207d755d41ec7056baaa19
- hash: 011870e1350719b0e79f6fb95cac8bfc
- hash: 029c7c50b9eeb99cf39388985ce202d3
- hash: 032f2eb7c9dff1ee6a4858451422b9d3
- hash: 0705be119dd534d819f2d58a819ed372
- hash: 0d6c53595f3bdd00eae7a48d5dd818fd
- hash: 0e379c45dabf5bb86c13947442fa02f7
- hash: 0f613ae429f1026badf95e560d836693
- hash: 0f95387dacb38f90f4e0029ece847d73
- hash: 12075ba8c42c0530ba771ce56799ec7d
- hash: 15e96d45d1bfb7cf50561e5e835d5c03
- hash: 21a8f4f786fd184eeae6e82a574e9539
- hash: 23cebd82cb3de56e34da7ab3bc799ddd
- hash: 2b863c18a04e99c8a2d68c3e1f52f9f6
- hash: 2c7d5f37e97ac2d4ff06ce5e6c9ed41c
- hash: 3224c1c3202adad76a770c9e251e1eaa
- hash: 32f0e9228a6df10f756e92d27539447b
- hash: 371e9e672213fbc58143cb0cdd8c1470
- hash: 38f16b1705af72c1f4bd0da77f6ca747
- hash: 3ac0b4155b0c6ba1d71fedc0c4efb76c
- hash: 3cc9a3dcb9b50a7d6b25c10def51663f
- hash: 3f5a1054ac9cdcb352cace4786a39f8c
- hash: 499171e37ec10ae6f52558581e773dfa
- hash: 4caac441ab918182d66647fb859ea09d
- hash: 4dadcd804f8ca1520dfb17e03fe77614
- hash: 520ff4ef2ce89178ad183c08540d195f
- hash: 5812051120aa1771d283ddd4b6e95888
- hash: 59517cc8c2ef8e7ecb0458ba3163cc43
- hash: 59997afec9e8d387d5545f756ed853d1
- hash: 5b3cdeb5e6921a3b699e37a168cc1a0b
- hash: 5c0cb4aecbfbf667429cf5b0cc882823
- hash: 5cf1c798a6cf980253b691be15906a15
- hash: 64f45faaaf9f055b78be59de0cc93c7a
- hash: 683e72b6c571f176437255dc842994d6
- hash: 6ba62002d1da83284b67e23e1c99003b
- hash: 6daddc1633633b7a57cfe70024c98385
- hash: 6fec5388338e7fad30b1e928251a0d2d
- hash: 700f7f88475bd00466a73aa44dfb6078
- hash: 74482d0dfd2b69d8eaee8030a7fd9527
- hash: 79290756492af5b9253d35fabde5b200
- hash: 7e71958c05c8524aef4910dd8e3886fa
- hash: 83cc0799f9b59001a8af3e1d9b0db46d
- hash: 86b9207d622beb86e010dd9e83fb76e1
- hash: 86fff0fe601bc6c16696a44af6b7cd3b
- hash: 89d3bbff2d31f0c6a497af93561f7896
- hash: 8a35c02f2b9bd96a36b371e9bafa6c3d
- hash: 8dc2a7c025ec2056cc276632834096bd
- hash: 914dec24177b2df1b6e7e737d52c5a0d
- hash: 965bf7a41741185e3408a67c26f128a4
- hash: 9e9b2f85b7cf810413cc3d2297df4a5d
- hash: a0943df236b7008d18cf63a1f8453ff5
- hash: a54e467bb154619331322efd10d72056
- hash: a5a07668ae46469a8cbf7d21f0e78455
- hash: ab38c3210def310454d767b941a8d6ed
- hash: ab7106cefb7432af40d5ebc35130e125
- hash: b160dfd974089d1bbc8fdcb259e433ba
- hash: b27396c120784902940e60f1c2d7ae39
- hash: b2c21b52c3460cbc71d0789eb50f3f51
- hash: b9f82d6aa01614103dc192261cdb80c3
- hash: bc8a0c41c982f8128c7af1e2796b12bb
- hash: bfe9854abb2654b684553c07097c0aae
- hash: c5efaf7695f0c2b1ce4a58039aacd021
- hash: c99afe8acd89069099c03fc91a4d9a87
- hash: d0045df35eb74ed22d63582d4ab4e211
- hash: d14e77be97e39691521e18ce01397516
- hash: d1a3f21e90281af466bc643ff07a35b7
- hash: d1a9268d87a361682785c3021b614de9
- hash: d758d83f6ef1d39e91841aa617a21f5c
- hash: d8be74a37c1f0244e5ef260996658d66
- hash: d9b5bb9cf87c918b3bd224c84e8696fb
- hash: da3b12034175f0c65a4ec4392e6a99d6
- hash: e089f24cd0ab580ab847ba03eb256331
- hash: e12cf99a75d37a0bfb324dd9dcf4ce15
- hash: ea8eb50777761cef110e28506bae1e8c
- hash: f0f510044af5db0a303e0a7e321021ed
- hash: f144c79df6d93c73069df00cdd8eddd9
- hash: f19b741aace40b5e18039b4596bbf2e5
- hash: f46f5e1e3fd7a100bb09c144e9eddae9
- hash: f747825a24052803266783f90ddaccba
- hash: f9576e5d0c96a54da008e8cc563ab3f8
- hash: 0012101ce836f096fbd5bf6083fb81e5aadfe112
- hash: 00173883febc1f6e7377dd06cf2feddb053770ec
- hash: 006d8eb48141537465358c9d80a8edb9776cd41d
- hash: 02c3599b6c61e25d0833e41ab26f78de54dc34f3
- hash: 063b4ef193cf08c3e24697ba71a4326670323bcb
- hash: 08f68d743aa35282be9fbd1a13d4dcd7d5e90fd9
- hash: 108b451edb21b8c9739d81c8eaad29c6e67e340d
- hash: 172852ee17c204f814738b87fccf47bac185e62b
- hash: 173dcaa5f4e2ee9a3beac3c983506d23b688f638
- hash: 1845125bc984a2c4bbc413fa7b2937077cff7dce
- hash: 1c46bf02aa0c7b4c73b1aefe9677e9ad9a8b005d
- hash: 1edf6353e175afc6f0c6152d984bf8ad73014256
- hash: 1f6d27e7d8687926eb7f684acf0a4c78e731b11d
- hash: 29a4a4322d1c2de93699b9c6c7547fb937db3d99
- hash: 2bc2be754c6b352858bb632d8512465553707d03
- hash: 2fae8162ecd5bad7354a9e7e9d9872732ebdd221
- hash: 3fec076b6b03d6eb94c6fafef09fa21a07071d33
- hash: 4c87dbf6f3bed0fb05f6aad8c2ac02c63c4c824f
- hash: 4e7db115175e64b4016d6d96db2df3c6c5898d17
- hash: 50bb7cd859e1b26f128ecca364421848921058e7
- hash: 56c0ed02b94b7d716652ef50058f4f8ac3830509
- hash: 57f5038c969b671861d72f2217c701752de7b6b2
- hash: 5ce451936eebeffe39f7f1d7e36d9f27f8e68a05
- hash: 5ffdce3c7f9ce6627ea607b28ec001309998e305
- hash: 6273a10f2d14e801fe72e47258a346c1b833d1b5
- hash: 64088f49ae1ce6ac5cf69d76605165062abe0879
- hash: 64fef6f4a08ad3f8aaf0dba7c334120bfebba18b
- hash: 6573e457235e0f0056da7927f8e295d72a6a1042
- hash: 678414ea62381a1cc8d2e750c4430653224bed15
- hash: 6f4e1b949d6a6e4775a8867d128ca8d270107786
- hash: 70bfc801d53b811853c87a1d653b99b97b138c30
- hash: 75dce0b6aec872ca3fb67a77dd666a77e7a25aa1
- hash: 78896c7d28095b035bfbf69e6d6e5be1b8f7f5d4
- hash: 7a8402a5ad8164d0fe86d949e13c01cea8db02c1
- hash: 7c71f8662c4c3c985799cee1dcfe79b65bf96041
- hash: 7c86d5f29d47945323b8f015f248922243fbfe0d
- hash: 7cd9d613f1acda6e89d07f1c849cd4e9112f15da
- hash: 7cda3c4d36dd9ade21dfc90cbd8cb657c66d9890
- hash: 7f707ad0d81d7613155104df7821f22c27e0c859
- hash: 83044780f1a6b131004033dfbe09b4956005dc0c
- hash: 83b53279ec2dd976d2b7cfad423909d8e48e221d
- hash: 8494b305d0698e519d4c7061d6c3d25bcb9db576
- hash: 85d36aa3dd7ce7657b03860acbe56d668926c730
- hash: 8ab62b23a7199b701ec65de535d6232ab7c42027
- hash: 8b81fe38c9910cbebb52a75cfc1a780489db78a5
- hash: 92544645b6a5fdf0abe82dae0243640a446b2d41
- hash: 92c51eec64045b98589f1b8099c360d942c80b7e
- hash: 95d29a5045bb5a9c37a7662dd06a1fb0f1322666
- hash: 9d99109cb44bbde8d12c2e762615d8e111c727eb
- hash: 9fbe3f0ee7cd2f259c9fb3393b143b651b75053b
- hash: a65ee5f85893bc1ee00239cde5801dbc47394bfc
- hash: a6a7d10f9fd86ab14fc15220d7879f5bb6017816
- hash: aae6ee2864865cf3a58cb467bd8e6e788cb570a7
- hash: ad60d582ed441b4ae08c57c67128a5140296be9a
- hash: af7ee70fc08080f7997472b4ab6137263ed96161
- hash: b06cf2266f2ab91a64f61a9beee79686895718d5
- hash: b19081ac7ea5c74b1369547035f9a0fe71b6702f
- hash: b6cacdaa900907097c7bbd2a34afd987731508bd
- hash: b8e418cd601d26147531f2f96cf2608024bb0af6
- hash: bcb6cbf59a39d9223ec63a59eeaba232d7983ebb
- hash: c278624f6b3a4ce7a4c446915d5a5baf9a06178a
- hash: c43d5e5d41af63ba772a084aa87bf91a1dc538d9
- hash: c6f89ce17aff2c2d9108b96376c09e19aca8f0f3
- hash: ccb203c050a84f41577db4be7f8377378175a0b7
- hash: ce172eea05fc961697609b8c88b9848c383695cd
- hash: cfa7c22e0c85ca0b3283f4bc728025d1dba5b130
- hash: d4db79f0a8b94cdf8e768f1aff8518afb1695ee8
- hash: d4ee0c27ec77ecbfa82482f19824e1c0ff8f1d29
- hash: de670f0026b752e0ab7e2705bb101f7614e965ed
- hash: e0d90c06094009eb67cfd45cf2fd2965b7de8693
- hash: e2825e605e21421c394d79baea987a3bb5c9d6e0
- hash: e40aee19e28898eda438a15b5b4576bf3402acd4
- hash: e69097f08f855080d84631fa3bcfc1e4130a91f2
- hash: e8f7f3b0c3add754f28225ae72c8aad1fff68728
- hash: ed2d06045c257e67c72bf989818a56039cd5c42e
- hash: ed3f64d8a65d81107913447c066e8b435b1263f6
- hash: f38e3be5d72f7c8e630d3a9ce4f1dcd01e2756aa
- hash: f57b257b2a528ee98f094cf728a940987ffe703c
- hash: f89442a16a0ae02e9933bffc69ecfc6b338e7dea
- hash: fdfbc4ab04df1cd7b724edfe73c576549aef2abd
- hash: ff8966f6a78ac3d8fb4e2dcdc9c03b60cf7378bc
- hash: 00bf35043ad23c7688d275bf19622a5e0fac4d05c85de4147ea4a6d8cb15a4d5
- hash: 0357a2b1aa898fce18ff9c011a56d22e5b1fa6edaa9518c8ca612cfc9aa1a727
- hash: 03854f44bb82bd540c36eaf917aa6ca77554da80c908717ada2cc447a9cd968a
- hash: 03fa7ea52b6684d83ddc1fcdb060f44a1f4bd7ac43c1c6664efb1a7ddc1c8bb4
- hash: 05be998ad8d0026527c4886e0a620a7f19cb5fbbf86450f4ed438089272c1146
- hash: 06a8af9818501234ba9df277ec8801dea787b8d2d2aa3daf373ffb8a6a17297f
- hash: 06ed1be7717382b57a8d3723d9ba4fd16b6da6915798f211cb912e0edda50250
- hash: 091778cb902d6e5c1bb82bde7491f57133c01085d8499e3efdbca9650a179f50
- hash: 0a37e694c0f931443ec6d885d0de33b5a1393a579a9bc185c8f2f3edcb274829
- hash: 0a58fff28500f9cb425dc552b4b43ebec119c88ff0454f077ca5df1a3fe93c51
- hash: 0adc1ccb533795da704f7559c6437d33c5696ca50017c8ac7183d977e87af198
- hash: 0ae56cf0362ac866c0267753060cf1013706c12c53c9fe451f2daab8abf914db
- hash: 0b28875dc8dc8184401e6841364bd866b748a816072aa3008b8f2bde8da306e5
- hash: 0b54c0030ed0784da63bd5cde33f24dd75a39bba1272c6642b1f1cf5a83f60d1
- hash: 0cccfcc2a5813d2617213d2c24fe96edd360ff23d25d4f6c5b7c2ad6f3f3e87e
- hash: 0cd560bbcb310da352b8d0bf91ca8241f47def12051716dc8a41cc9a2ff6948c
- hash: 0d9ee0960f8560e85affcd6ee06b9bc06fdb579f0243270ba85ad4c34b1e199f
- hash: 0e1d086d61384d892a97395f22caa569ac16aad4d0dd83fe93cd3043e58de951
- hash: 10c873fe71ec276259331ec99d52e713843c8a2c035855c8b7578210001c55bf
- hash: 1381aefa4e5d231e8ac360ee8400ee7d73238dd68b51b76076735a0394f73eb6
- hash: 1429b05b2d9b5e313e7d72e4c780571a7e28c6603bf37602526791c0621f3f75
- hash: 15caa907e07ed1834df5f5df1bcb85187083d0b81d0825a39a9498ffa96a20f8
- hash: 16dcc89e8b8e5e530e835b77d8160d903d12994009228a446d17eb267ad8b168
- hash: 185df325ec3a346ba7f071af08828d3efff08a56ec2587d0d5321fec08d24e27
- hash: 1b65e5039434f955bd688b0fb20411c0938e33c598c86fd70fc6680ed4c7f900
- hash: 1c6ff5e35c3f042b8830c623afc41c0e430b1c2c4608a83f9dcb5ff4d82dc937
- hash: 23599a2ed23a230b426e9e17ae4feeafa4a841b9818a6946392dc3bd03632613
- hash: 235d76baad46719e400e7a6f0872dec11a5003d9638a6c7a1e085d7fd3244ef6
- hash: 25e046fdd40c97473d04b60d171863411f046fe25e299e09f5d3ec99c78ecb2d
- hash: 265b705b47dad7bf22e8db182acf6c8346b2edc9a6722a780cbf4270fc82961d
- hash: 2943dd40dff9ee74ddc956662e41da0b839996ea37cc2f56f0e9258fddb86262
- hash: 2a282d3699c6936d128bc3e78e3dbd5849c51317383305c2e017d038c8944ef8
- hash: 2a79aff27e084de07a0d20704c2115fcfa78fd0204aa3a07c83c4eb64ff3e8f2
- hash: 2c9f68681d1d2375dabf259c7a88b1f3ae33af9d5be5fdf5fc01d0a7a0c45247
- hash: 329da394e260170fcd1ec9c36c6726a786704d1d1c499b5c4cb8c936b4191ff6
- hash: 338800bd013fc0bc8bad5e6cfaa723c6a0d35ebbe8c2ba05ca10c03b0886d8a3
- hash: 34b8d12f85d96013fa87fb3a12c920fe537ff91b6493529d9e531cdb724a3d9f
- hash: 34b94d6c965abfad3381a95503a82a4a44d5c83795efb55b54c308dfc5d2e260
- hash: 35c5ccf843a1e1cca3036ea8482dc2241b3dec8df1e04eaf782fdbb7f780ac3e
- hash: 37f75aa2612ebb4ad99a732b8891308ff9594d44d3d7a2f53536203fc95c4b16
- hash: 3972038428bff011253cec28813f37da2bcadede72bd64d4030cba1d1f7c36f4
- hash: 3b7b9d3ddecfd67686c9fc78e021c02b9ca3b3a33215236e86f4e1ca50385662
- hash: 426f9ac9f873c9e7d316065b5cac39e0027a9c9dec21b3b96b6db345e196cd89
- hash: 43594723a67f6fcabc0f7555adb7df9a0487df1873b9669a8d977d1bf385e12a
- hash: 43970535ad69ef05fcc3c5318f4e2b2bb92eddcbb029b9bd6fd79a652be94c5d
- hash: 492a132deb06232d73b2830633aae721062898caf5b95864b4fa1c0a823b06ff
- hash: 4e27035796c6bf7c88758af2370acb3e0ec98d1b84d3f19f34336df0af8bc067
- hash: 4f76ebd328ac11b5a3228ab52434ce57d46e436dc76c3c25a4b45e3cf046cdeb
- hash: 4fc0a3ba8be36fbeeb31b0b4a250ce9a1d0bfc2110d2180d4d3f96e4d0e87c93
- hash: 51678577b43986cdcfc5fedd47cee5bc007221c7ee2fc2bc94b1b19317a6c055
- hash: 557a278750174d4ae058a7e11febd28e3c296c801e5ef319a1e0be9497093489
- hash: 56c4afbd4d99698eaf1efaa0d6654c5969fdf893072b39e6e301a60b25a91996
- hash: 578a2d1f389adb6b514a8491e771db100ef5e13a9b9dc5bcb57d1e83dcbef0fd
- hash: 59900f715ba9704963b403b46518bf9acdcabcb76472066a2479dfe8c00e02b0
- hash: 5e39dfab5879138ce94d2f6918679f7e69c8ee50715d4bc48e0f0f20dab21c34
- hash: 60bd3b2945a04bf99fd7ab801e47f8b1372c03dbd3f168b7eec12e0c057f6e38
- hash: 639830080e6efdb718ec5aeb4e03c5e7721246919dba066effd1d1280a13962d
- hash: 64f2d69a665b77c16569c0c28e3ceb8a061c0b1d9ec306b89fc7deddaf55bbe6
- hash: 68c142aecd006c86c0f28a8662bee5f7b94beeeac27b8e356901fb8ac0425b59
- hash: 6b79afe0b533307cd0ec396655131c7f49e8c480de04b6cdca2e0f1353968040
- hash: 6d80ae4403f6813bc9acd49729548b92759f0198ffbff0e4c295d7df660f4fd3
- hash: 6d8cba92107b8d1ac72052bfc9326bebcb24ee75b0fc3bb6d890cec5e9ab380a
- hash: 6e7244523e8b853c4bc3dd655f5dd40b59fee0b9e1fa70c8bf829dee315d731e
- hash: 6f641749f3d85c9693f126e05eb426d55e986d180ebd9a6e84dbf10a4b568a19
- hash: 712332746cf76edb6deaa49b59662e505a2b9f366226e9b0e020e85dda90d9ff
- hash: 714e7f13188d618d80698e909e1a7bcc80cfc073fc84dc7762062c134490dcab
- hash: 72f149969ef2173dc29d436135d5ce39adcc82fca1b3a7abae66150d95af6035
- hash: 7409846a292d79be09911952ef795a1a56e5064ee03d4da3025c09df51a19e4d
- hash: 75798ec92779e8af81de5906c6f35dffd8bbabe741e8ac821887924be2a079ff
- hash: 776df17dcfb99b5cc06d1ff75528955ca51b5f6d115ec4e6ff0151fff4190c30
- hash: 7982c897c5bc8f3b31fc610b9cada477c8a8b66138aa5dba47ea6526152318ac
- hash: 79b608e1a1c8d3f839ef31dd94eae3526f69a9298c8d9f2f86d9050e77232d4b
- hash: 79e0231d25d7588fa17037f64b69d85c08940b5fe3b7672a4366c9e012d353b8
- hash: 7d4c946027003c720a3ec8c357b8cd4ca821e950876f06b1cb5bef9df2118dc9
- hash: 7ea73c32040727b17ed265fb4a3f9b2cc314a97665b5d707d43adc0391e80915
- hash: 7ee145ad0db7184704b3d1dba4d8399d1803424a02d621229cc895b467a1550b
- hash: 809eb1c5776d97da66b6ccf8df655aed555f1bff42dca18f8a7fdbc90a528ccb
- hash: 80ec9992a61fa47f222ed879bd7f948d321e27517ce3c08231e48127ac6dca39
- hash: 828a1a643102009be7c236bc29789972b3c3cf10a8638bf0baaf1f009684369d
- hash: 844edd67c98220c02ebce13a83dae14e9f01077916e61c5c658550524eb374bd
- hash: 888537d9a0d0983584f335eb4abcc1cccbbc653e5424b00b14d5b885f0995b85
- hash: 8ac670705f940ab1edb850331595f8b4ac906678fd63e4ab8fae03975420de44
- hash: 8be0af109d3f166ea7ca3968963c9ef01a6441bb941b1399f2bf8f3902dbfce2
- hash: 8c85425368d710441baaafea617480367f28bc26a54899568c4d62ecaeb65021
- hash: 8d96d0d7a8d6b0717e6f75f60a3889e86a4203aa8aab0e9349b70e38ad8ddf8f
- hash: 8e19cd717704dd9907491a69505d5920208fb94506f7f0b9404d24adbb430625
- hash: 91e18fc48a0ee20c62ccc955f4aa401ec4080f2f47da99a1ffc381af888c4b17
- hash: 937e75558fede0ab3a043c022e61aac840493ca7335166a320646598266eb2ba
- hash: 93e642fbe2bd6e1da0e7d17c843c647ab01b7f2484396bbf007f73d34ff4ea41
- hash: 977c1ba6fe57f66b24df90039b6f6af4587ef4b1672bfb6035f612fd1cf7fbd1
- hash: 9b6430da65a521fa76b3d4702a70974b913420fdc1e327547600606b80ba64d2
- hash: 9bf6fa1f35a73e5665e0cf8512e576a0f5cb99af31d05ee0640a74de960bb38c
- hash: 9da8e036443eebab49e86d4f605260a18b44dd1e0ee6cde6736dd942203a74cd
- hash: 9e2ad1d34fb87a26f99895466d4cb81b879d3540efa03ebdad1a40d4117646a2
- hash: 9e5539de48ed2120dec5f3382c3675fb6cfcfa6e4fb11cc9b9785cc584dbfa39
- hash: a0a88b64b05c0ecdb12d41fcc4e19d1cdd09ebac70be571a7ad8e50c50bd2d7e
- hash: a2b09bc35afdd001d708897e29c26f531b7c5384606bb523535339f93452f1ce
- hash: a6bc4f4f62999fb8f8d04befc96677abf786b8f5ecda7ad4bd59ed94abf09297
- hash: a770962691edc713ffbba74b855ae59bc32735a7e6524282a5a1f813e971a313
- hash: a9d7504f012749ff50b12fee1e129eb676763355f836321822ab77b6fb7ef9ac
- hash: abad58d56f65025d6eef0bb5b6402f6e0f34463cc331dc0fe696472ab768f63f
- hash: b011de113a0ba863bb987f21b75b1ffa835f69c02a856a5b91c61b6a8549da2e
- hash: b2e6d7becd9a7bd1411118e179c28f5c96ae529cfba5f562a0384a5bd0c038e0
- hash: b31b5644d5e88caa45941921d97c05696adefe884f11a946c9f00141d959caec
- hash: b3308c165e46332fe6a19ca222f4bda0d193b035b8dc1c2135a4005d7d65864c
- hash: b5542dd5d015d8a5b1405973d9dcf5a94dccdcc970f43b4197e5dbc2dff3028a
- hash: ba38e037657db285c00c4e737c10c467908383c81e771b75ee039b1b8e595f4b
- hash: bc264399a8d894ba8baf6861c16a17df91935895b3a44c401654787ee78fddd0
- hash: beeb2632662a2c4088e6df90788b290948717b192c0bbe1e9ba3e9390ff5dbd0
- hash: bf3d9bb02996a45e1e7e0b89dae32a6fc5faceb413d8bbbfca35889078bd7a96
- hash: c0a86bee959f299518129d3220f5a2cb2a2d74ccce80586ce4db5f5215b97c94
- hash: c0fdb5ae93508123a0ccb87d470ef12a1a6048592bb3e67855335c79a60e138c
- hash: c34baac5ee3212c7acbc4b3a7b2a27336f1c693327c675a5e4e4b822f964d801
- hash: c640b4d8201c8a738d50f7cc8f842a4875ff24c5440f152cecce4af99f3ddbdd
- hash: ca33271f15d966b2da95010748d62e5e72c4783c74715953e4f79264cde54cef
- hash: cb43b4165208d878c1bbd39a6e45de1efa3cda9f334c5bfb4e9adf59b55a976b
- hash: cc73a3d2fc03fc38c58f27d98274680eb84b77fc4ad6dd424f88984effa2d1bb
- hash: cc97fd7febd8ddce86ac7685a10c060346e1aec7059f2dcfbdc56ec415db7a8e
- hash: ccf4d4142892222f1f7d6c196338065ae55e3296f03bb8875345f6fd485917ef
- hash: cec5ccc08f96fa9fa697f7d146283566b31c1a322276bc56d47617d31889b424
- hash: d36a4b75a39c59382d4f96b119849d1151ecd68b409c846a551f0b2d47ef1949
- hash: d49677515a17747af85c703ae62f36ce5a8bdb80056e6f3b3057f4380866cbea
- hash: d80fbf09bd877c73e6e934af66176b23e9ff9843b110936b6ad5bffbd849bce9
- hash: dc6d9730a652a7b39b636cb3ee50b6d5fa04e3882a1f4078048968928f96fa6e
- hash: deb65779808d584ec755e8cb6a78f8df7fe8105d80e454a0763d34f6c49a893f
- hash: e16902ef4070386cd90dd7d66ebe1fe90f94f532bc547152fb24cf9f92c1ef77
- hash: e269d4d75f3c05b2b86b924251d7107c635cce57f6aea83d518921eccf04b57b
- hash: e3fe38399beafd74c35c9dc9350df9cf4be40be2378cfc4b915afee5d417bd8e
- hash: e7923de87700df0de640ef2499a8dd9d86f0f000e98bd3242efbe8b96b6e61b6
- hash: e87fed756fb4ddf14405f4edf90a4c661c34c972d84d9ca7c0c762fae8b5f87f
- hash: e8fedceccca49458bfce4f4c3243460caf9d5d4341e63fd572d553a702a72c30
- hash: e9d8e1c00faa8d4eb4af0f389da9165bcc99a1754b1eb58b5f6a235e33e03d4b
- hash: ec8bb702cca9a92516f8474e708acbe6e1f4987adc8aac6c549d752397cec139
- hash: efab8707fb01291ba00481145766260ec0a125394551c63b216da2d2daf50ebc
- hash: f03145e889d6098142a9872aab774643afcdb3a32535c0d5b3ce322eb0c3bab2
- hash: f2fd583c9c9059bd3ca02df23384e1e5694675c63cb4852185db6ffd5ec1311d
- hash: f359a4067ef66ffa80a3000a60a30f2dd31a7eb8ec5b2df8579e609cfaf9728a
- hash: f459ff9867b08eb2a7b8f33eb97d6ad782ad9066cf316c5b584f264fbfd91291
- hash: f71cda0b52b11c30fd34af51ea82b1c2fd13ab2fd0120cbf361dce34bffae73a
- hash: f822ec9f04aee7f29f93dbd6ab235ce92ba4446c2d0be52f7d9be64d8da30789
- hash: f88a99d94b4bd5ac0f916e8128ad3735604531ee38e0731d672d5fc4f607e69e
- hash: fa2f7614462ef071aa4d7032128edce12889f7a677ce16c0a0a1ccc7e1c4fa5d
- hash: fb4a36fbdcf51c9847d94c0fcf8d62045a5ab781b7b1695eaed5b22f21d34ed9
- hash: fda55c91ceb9524f1cc99ccfddcd287f1e1a8078b48ff86895905b18109a1cf4
- hash: fe1f2d47ee0ab4c27f10487643d4f956057af31e989fa39e9a8686a6fdbc633a
- url: http://goolgepalay.com
- url: http://tiktokgplya.sbs
- url: https://bjsffsj.sbs
- url: https://fantasy-hub.online
- url: https://fantasy-hub.ru
- url: https://telegramunlock.ru
- url: https://tikitok-goolges.sbs
- url: https://tikpremplaymarktuzb.sbs
- url: https://tiktoki-goolge.sbs
- url: https://unlockk.play-google-store.ru
- url: https://wildberries.play-market-com.online
- url: https://www.tikitok-playgoolge.sbs
- domain: bjsffsj.sbs
- domain: fantasy-hub.online
- domain: fantasy-hub.ru
- domain: goolgepalay.com
- domain: telegramunlock.ru
- domain: tikitok-goolges.sbs
- domain: tikpremplaymarktuzb.sbs
- domain: tiktokgplya.sbs
- domain: tiktoki-goolge.sbs
- domain: unlockk.play-google-store.ru
- domain: wildberries.play-market-com.online
- domain: www.tikitok-playgoolge.sbs
Fantasy Hub: Another Russian Based RAT as Malware-as-a-Service
Description
Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected.
AI-Powered Analysis
Technical Analysis
Fantasy Hub is an Android-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) subscription model on Russian-language channels. This RAT provides attackers with extensive control over infected devices, including the ability to exfiltrate SMS messages, steal contacts and call logs, and bulk download images and videos. It also intercepts, replies to, and deletes incoming notifications, which can be used to manipulate victim communications stealthily. The malware employs social engineering tactics by creating fake Google Play Store pages to trick users into installing the RAT, thereby evading traditional detection mechanisms. A key focus of Fantasy Hub is targeting financial institutions by deploying fake windows designed to capture banking credentials, enabling financial fraud. The MaaS offering includes detailed seller documentation, instructional videos, and a bot-driven subscription system, making the malware accessible even to attackers with limited technical skills. Although no confirmed exploits in the wild have been documented, the combination of advanced espionage features and ease of deployment presents a significant threat. The RAT’s capabilities allow attackers to compromise confidentiality, integrity, and availability of user data on Android devices, particularly those used for sensitive financial transactions.
Potential Impact
For European organizations, especially financial institutions, Fantasy Hub represents a significant threat to the confidentiality and integrity of sensitive data. The malware’s ability to steal banking credentials and intercept communications can lead to financial fraud, identity theft, and unauthorized access to corporate networks. The exfiltration of SMS, contacts, and call logs can also facilitate broader espionage campaigns and social engineering attacks. Given the widespread use of Android devices across Europe, including in corporate environments, the potential attack surface is large. The stealth features, such as notification interception and fake app pages, increase the likelihood of successful infections and prolonged undetected presence on devices. This can undermine trust in mobile banking applications and disrupt normal business operations. Additionally, the MaaS model lowers the barrier for entry, potentially increasing the volume of attacks originating from less skilled threat actors.
Mitigation Recommendations
European organizations should implement multi-layered mobile security strategies focused on detection and prevention of RAT infections. Specific measures include deploying mobile threat defense (MTD) solutions capable of detecting fake app stores and suspicious app behavior. User education campaigns should emphasize the risks of installing apps from unofficial sources and recognizing phishing attempts involving fake Google Play pages. Financial institutions should enforce multi-factor authentication (MFA) for mobile banking apps to reduce the impact of credential theft. Network-level protections such as DNS filtering and blocking known malicious domains associated with Fantasy Hub can limit command and control communications. Regular monitoring of mobile device logs for unusual notification activity or unauthorized access attempts can aid early detection. Incident response plans should include procedures for isolating infected devices and conducting forensic analysis. Collaboration with threat intelligence providers to stay updated on emerging indicators of compromise (IOCs) related to Fantasy Hub is also recommended.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://github.com/Zimperium/IOC/blob/master/2025-11-FantasyHUB/hosts.csv","https://zimperium.com/blog/fantasy-hub-another-russian-based-rat-as-m-a-a-s","https://github.com/Zimperium/IOC/blob/master/2025-11-FantasyHUB/apks.csv"]
- Adversary
- null
- Pulse Id
- 6911cdc11d3b1ec1aa03d9bf
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash00ba72f40855e703c318cabb441af736 | — | |
hash00ef76ea4e207d755d41ec7056baaa19 | — | |
hash011870e1350719b0e79f6fb95cac8bfc | — | |
hash029c7c50b9eeb99cf39388985ce202d3 | — | |
hash032f2eb7c9dff1ee6a4858451422b9d3 | — | |
hash0705be119dd534d819f2d58a819ed372 | — | |
hash0d6c53595f3bdd00eae7a48d5dd818fd | — | |
hash0e379c45dabf5bb86c13947442fa02f7 | — | |
hash0f613ae429f1026badf95e560d836693 | — | |
hash0f95387dacb38f90f4e0029ece847d73 | — | |
hash12075ba8c42c0530ba771ce56799ec7d | — | |
hash15e96d45d1bfb7cf50561e5e835d5c03 | — | |
hash21a8f4f786fd184eeae6e82a574e9539 | — | |
hash23cebd82cb3de56e34da7ab3bc799ddd | — | |
hash2b863c18a04e99c8a2d68c3e1f52f9f6 | — | |
hash2c7d5f37e97ac2d4ff06ce5e6c9ed41c | — | |
hash3224c1c3202adad76a770c9e251e1eaa | — | |
hash32f0e9228a6df10f756e92d27539447b | — | |
hash371e9e672213fbc58143cb0cdd8c1470 | — | |
hash38f16b1705af72c1f4bd0da77f6ca747 | — | |
hash3ac0b4155b0c6ba1d71fedc0c4efb76c | — | |
hash3cc9a3dcb9b50a7d6b25c10def51663f | — | |
hash3f5a1054ac9cdcb352cace4786a39f8c | — | |
hash499171e37ec10ae6f52558581e773dfa | — | |
hash4caac441ab918182d66647fb859ea09d | — | |
hash4dadcd804f8ca1520dfb17e03fe77614 | — | |
hash520ff4ef2ce89178ad183c08540d195f | — | |
hash5812051120aa1771d283ddd4b6e95888 | — | |
hash59517cc8c2ef8e7ecb0458ba3163cc43 | — | |
hash59997afec9e8d387d5545f756ed853d1 | — | |
hash5b3cdeb5e6921a3b699e37a168cc1a0b | — | |
hash5c0cb4aecbfbf667429cf5b0cc882823 | — | |
hash5cf1c798a6cf980253b691be15906a15 | — | |
hash64f45faaaf9f055b78be59de0cc93c7a | — | |
hash683e72b6c571f176437255dc842994d6 | — | |
hash6ba62002d1da83284b67e23e1c99003b | — | |
hash6daddc1633633b7a57cfe70024c98385 | — | |
hash6fec5388338e7fad30b1e928251a0d2d | — | |
hash700f7f88475bd00466a73aa44dfb6078 | — | |
hash74482d0dfd2b69d8eaee8030a7fd9527 | — | |
hash79290756492af5b9253d35fabde5b200 | — | |
hash7e71958c05c8524aef4910dd8e3886fa | — | |
hash83cc0799f9b59001a8af3e1d9b0db46d | — | |
hash86b9207d622beb86e010dd9e83fb76e1 | — | |
hash86fff0fe601bc6c16696a44af6b7cd3b | — | |
hash89d3bbff2d31f0c6a497af93561f7896 | — | |
hash8a35c02f2b9bd96a36b371e9bafa6c3d | — | |
hash8dc2a7c025ec2056cc276632834096bd | — | |
hash914dec24177b2df1b6e7e737d52c5a0d | — | |
hash965bf7a41741185e3408a67c26f128a4 | — | |
hash9e9b2f85b7cf810413cc3d2297df4a5d | — | |
hasha0943df236b7008d18cf63a1f8453ff5 | — | |
hasha54e467bb154619331322efd10d72056 | — | |
hasha5a07668ae46469a8cbf7d21f0e78455 | — | |
hashab38c3210def310454d767b941a8d6ed | — | |
hashab7106cefb7432af40d5ebc35130e125 | — | |
hashb160dfd974089d1bbc8fdcb259e433ba | — | |
hashb27396c120784902940e60f1c2d7ae39 | — | |
hashb2c21b52c3460cbc71d0789eb50f3f51 | — | |
hashb9f82d6aa01614103dc192261cdb80c3 | — | |
hashbc8a0c41c982f8128c7af1e2796b12bb | — | |
hashbfe9854abb2654b684553c07097c0aae | — | |
hashc5efaf7695f0c2b1ce4a58039aacd021 | — | |
hashc99afe8acd89069099c03fc91a4d9a87 | — | |
hashd0045df35eb74ed22d63582d4ab4e211 | — | |
hashd14e77be97e39691521e18ce01397516 | — | |
hashd1a3f21e90281af466bc643ff07a35b7 | — | |
hashd1a9268d87a361682785c3021b614de9 | — | |
hashd758d83f6ef1d39e91841aa617a21f5c | — | |
hashd8be74a37c1f0244e5ef260996658d66 | — | |
hashd9b5bb9cf87c918b3bd224c84e8696fb | — | |
hashda3b12034175f0c65a4ec4392e6a99d6 | — | |
hashe089f24cd0ab580ab847ba03eb256331 | — | |
hashe12cf99a75d37a0bfb324dd9dcf4ce15 | — | |
hashea8eb50777761cef110e28506bae1e8c | — | |
hashf0f510044af5db0a303e0a7e321021ed | — | |
hashf144c79df6d93c73069df00cdd8eddd9 | — | |
hashf19b741aace40b5e18039b4596bbf2e5 | — | |
hashf46f5e1e3fd7a100bb09c144e9eddae9 | — | |
hashf747825a24052803266783f90ddaccba | — | |
hashf9576e5d0c96a54da008e8cc563ab3f8 | — | |
hash0012101ce836f096fbd5bf6083fb81e5aadfe112 | — | |
hash00173883febc1f6e7377dd06cf2feddb053770ec | — | |
hash006d8eb48141537465358c9d80a8edb9776cd41d | — | |
hash02c3599b6c61e25d0833e41ab26f78de54dc34f3 | — | |
hash063b4ef193cf08c3e24697ba71a4326670323bcb | — | |
hash08f68d743aa35282be9fbd1a13d4dcd7d5e90fd9 | — | |
hash108b451edb21b8c9739d81c8eaad29c6e67e340d | — | |
hash172852ee17c204f814738b87fccf47bac185e62b | — | |
hash173dcaa5f4e2ee9a3beac3c983506d23b688f638 | — | |
hash1845125bc984a2c4bbc413fa7b2937077cff7dce | — | |
hash1c46bf02aa0c7b4c73b1aefe9677e9ad9a8b005d | — | |
hash1edf6353e175afc6f0c6152d984bf8ad73014256 | — | |
hash1f6d27e7d8687926eb7f684acf0a4c78e731b11d | — | |
hash29a4a4322d1c2de93699b9c6c7547fb937db3d99 | — | |
hash2bc2be754c6b352858bb632d8512465553707d03 | — | |
hash2fae8162ecd5bad7354a9e7e9d9872732ebdd221 | — | |
hash3fec076b6b03d6eb94c6fafef09fa21a07071d33 | — | |
hash4c87dbf6f3bed0fb05f6aad8c2ac02c63c4c824f | — | |
hash4e7db115175e64b4016d6d96db2df3c6c5898d17 | — | |
hash50bb7cd859e1b26f128ecca364421848921058e7 | — | |
hash56c0ed02b94b7d716652ef50058f4f8ac3830509 | — | |
hash57f5038c969b671861d72f2217c701752de7b6b2 | — | |
hash5ce451936eebeffe39f7f1d7e36d9f27f8e68a05 | — | |
hash5ffdce3c7f9ce6627ea607b28ec001309998e305 | — | |
hash6273a10f2d14e801fe72e47258a346c1b833d1b5 | — | |
hash64088f49ae1ce6ac5cf69d76605165062abe0879 | — | |
hash64fef6f4a08ad3f8aaf0dba7c334120bfebba18b | — | |
hash6573e457235e0f0056da7927f8e295d72a6a1042 | — | |
hash678414ea62381a1cc8d2e750c4430653224bed15 | — | |
hash6f4e1b949d6a6e4775a8867d128ca8d270107786 | — | |
hash70bfc801d53b811853c87a1d653b99b97b138c30 | — | |
hash75dce0b6aec872ca3fb67a77dd666a77e7a25aa1 | — | |
hash78896c7d28095b035bfbf69e6d6e5be1b8f7f5d4 | — | |
hash7a8402a5ad8164d0fe86d949e13c01cea8db02c1 | — | |
hash7c71f8662c4c3c985799cee1dcfe79b65bf96041 | — | |
hash7c86d5f29d47945323b8f015f248922243fbfe0d | — | |
hash7cd9d613f1acda6e89d07f1c849cd4e9112f15da | — | |
hash7cda3c4d36dd9ade21dfc90cbd8cb657c66d9890 | — | |
hash7f707ad0d81d7613155104df7821f22c27e0c859 | — | |
hash83044780f1a6b131004033dfbe09b4956005dc0c | — | |
hash83b53279ec2dd976d2b7cfad423909d8e48e221d | — | |
hash8494b305d0698e519d4c7061d6c3d25bcb9db576 | — | |
hash85d36aa3dd7ce7657b03860acbe56d668926c730 | — | |
hash8ab62b23a7199b701ec65de535d6232ab7c42027 | — | |
hash8b81fe38c9910cbebb52a75cfc1a780489db78a5 | — | |
hash92544645b6a5fdf0abe82dae0243640a446b2d41 | — | |
hash92c51eec64045b98589f1b8099c360d942c80b7e | — | |
hash95d29a5045bb5a9c37a7662dd06a1fb0f1322666 | — | |
hash9d99109cb44bbde8d12c2e762615d8e111c727eb | — | |
hash9fbe3f0ee7cd2f259c9fb3393b143b651b75053b | — | |
hasha65ee5f85893bc1ee00239cde5801dbc47394bfc | — | |
hasha6a7d10f9fd86ab14fc15220d7879f5bb6017816 | — | |
hashaae6ee2864865cf3a58cb467bd8e6e788cb570a7 | — | |
hashad60d582ed441b4ae08c57c67128a5140296be9a | — | |
hashaf7ee70fc08080f7997472b4ab6137263ed96161 | — | |
hashb06cf2266f2ab91a64f61a9beee79686895718d5 | — | |
hashb19081ac7ea5c74b1369547035f9a0fe71b6702f | — | |
hashb6cacdaa900907097c7bbd2a34afd987731508bd | — | |
hashb8e418cd601d26147531f2f96cf2608024bb0af6 | — | |
hashbcb6cbf59a39d9223ec63a59eeaba232d7983ebb | — | |
hashc278624f6b3a4ce7a4c446915d5a5baf9a06178a | — | |
hashc43d5e5d41af63ba772a084aa87bf91a1dc538d9 | — | |
hashc6f89ce17aff2c2d9108b96376c09e19aca8f0f3 | — | |
hashccb203c050a84f41577db4be7f8377378175a0b7 | — | |
hashce172eea05fc961697609b8c88b9848c383695cd | — | |
hashcfa7c22e0c85ca0b3283f4bc728025d1dba5b130 | — | |
hashd4db79f0a8b94cdf8e768f1aff8518afb1695ee8 | — | |
hashd4ee0c27ec77ecbfa82482f19824e1c0ff8f1d29 | — | |
hashde670f0026b752e0ab7e2705bb101f7614e965ed | — | |
hashe0d90c06094009eb67cfd45cf2fd2965b7de8693 | — | |
hashe2825e605e21421c394d79baea987a3bb5c9d6e0 | — | |
hashe40aee19e28898eda438a15b5b4576bf3402acd4 | — | |
hashe69097f08f855080d84631fa3bcfc1e4130a91f2 | — | |
hashe8f7f3b0c3add754f28225ae72c8aad1fff68728 | — | |
hashed2d06045c257e67c72bf989818a56039cd5c42e | — | |
hashed3f64d8a65d81107913447c066e8b435b1263f6 | — | |
hashf38e3be5d72f7c8e630d3a9ce4f1dcd01e2756aa | — | |
hashf57b257b2a528ee98f094cf728a940987ffe703c | — | |
hashf89442a16a0ae02e9933bffc69ecfc6b338e7dea | — | |
hashfdfbc4ab04df1cd7b724edfe73c576549aef2abd | — | |
hashff8966f6a78ac3d8fb4e2dcdc9c03b60cf7378bc | — | |
hash00bf35043ad23c7688d275bf19622a5e0fac4d05c85de4147ea4a6d8cb15a4d5 | — | |
hash0357a2b1aa898fce18ff9c011a56d22e5b1fa6edaa9518c8ca612cfc9aa1a727 | — | |
hash03854f44bb82bd540c36eaf917aa6ca77554da80c908717ada2cc447a9cd968a | — | |
hash03fa7ea52b6684d83ddc1fcdb060f44a1f4bd7ac43c1c6664efb1a7ddc1c8bb4 | — | |
hash05be998ad8d0026527c4886e0a620a7f19cb5fbbf86450f4ed438089272c1146 | — | |
hash06a8af9818501234ba9df277ec8801dea787b8d2d2aa3daf373ffb8a6a17297f | — | |
hash06ed1be7717382b57a8d3723d9ba4fd16b6da6915798f211cb912e0edda50250 | — | |
hash091778cb902d6e5c1bb82bde7491f57133c01085d8499e3efdbca9650a179f50 | — | |
hash0a37e694c0f931443ec6d885d0de33b5a1393a579a9bc185c8f2f3edcb274829 | — | |
hash0a58fff28500f9cb425dc552b4b43ebec119c88ff0454f077ca5df1a3fe93c51 | — | |
hash0adc1ccb533795da704f7559c6437d33c5696ca50017c8ac7183d977e87af198 | — | |
hash0ae56cf0362ac866c0267753060cf1013706c12c53c9fe451f2daab8abf914db | — | |
hash0b28875dc8dc8184401e6841364bd866b748a816072aa3008b8f2bde8da306e5 | — | |
hash0b54c0030ed0784da63bd5cde33f24dd75a39bba1272c6642b1f1cf5a83f60d1 | — | |
hash0cccfcc2a5813d2617213d2c24fe96edd360ff23d25d4f6c5b7c2ad6f3f3e87e | — | |
hash0cd560bbcb310da352b8d0bf91ca8241f47def12051716dc8a41cc9a2ff6948c | — | |
hash0d9ee0960f8560e85affcd6ee06b9bc06fdb579f0243270ba85ad4c34b1e199f | — | |
hash0e1d086d61384d892a97395f22caa569ac16aad4d0dd83fe93cd3043e58de951 | — | |
hash10c873fe71ec276259331ec99d52e713843c8a2c035855c8b7578210001c55bf | — | |
hash1381aefa4e5d231e8ac360ee8400ee7d73238dd68b51b76076735a0394f73eb6 | — | |
hash1429b05b2d9b5e313e7d72e4c780571a7e28c6603bf37602526791c0621f3f75 | — | |
hash15caa907e07ed1834df5f5df1bcb85187083d0b81d0825a39a9498ffa96a20f8 | — | |
hash16dcc89e8b8e5e530e835b77d8160d903d12994009228a446d17eb267ad8b168 | — | |
hash185df325ec3a346ba7f071af08828d3efff08a56ec2587d0d5321fec08d24e27 | — | |
hash1b65e5039434f955bd688b0fb20411c0938e33c598c86fd70fc6680ed4c7f900 | — | |
hash1c6ff5e35c3f042b8830c623afc41c0e430b1c2c4608a83f9dcb5ff4d82dc937 | — | |
hash23599a2ed23a230b426e9e17ae4feeafa4a841b9818a6946392dc3bd03632613 | — | |
hash235d76baad46719e400e7a6f0872dec11a5003d9638a6c7a1e085d7fd3244ef6 | — | |
hash25e046fdd40c97473d04b60d171863411f046fe25e299e09f5d3ec99c78ecb2d | — | |
hash265b705b47dad7bf22e8db182acf6c8346b2edc9a6722a780cbf4270fc82961d | — | |
hash2943dd40dff9ee74ddc956662e41da0b839996ea37cc2f56f0e9258fddb86262 | — | |
hash2a282d3699c6936d128bc3e78e3dbd5849c51317383305c2e017d038c8944ef8 | — | |
hash2a79aff27e084de07a0d20704c2115fcfa78fd0204aa3a07c83c4eb64ff3e8f2 | — | |
hash2c9f68681d1d2375dabf259c7a88b1f3ae33af9d5be5fdf5fc01d0a7a0c45247 | — | |
hash329da394e260170fcd1ec9c36c6726a786704d1d1c499b5c4cb8c936b4191ff6 | — | |
hash338800bd013fc0bc8bad5e6cfaa723c6a0d35ebbe8c2ba05ca10c03b0886d8a3 | — | |
hash34b8d12f85d96013fa87fb3a12c920fe537ff91b6493529d9e531cdb724a3d9f | — | |
hash34b94d6c965abfad3381a95503a82a4a44d5c83795efb55b54c308dfc5d2e260 | — | |
hash35c5ccf843a1e1cca3036ea8482dc2241b3dec8df1e04eaf782fdbb7f780ac3e | — | |
hash37f75aa2612ebb4ad99a732b8891308ff9594d44d3d7a2f53536203fc95c4b16 | — | |
hash3972038428bff011253cec28813f37da2bcadede72bd64d4030cba1d1f7c36f4 | — | |
hash3b7b9d3ddecfd67686c9fc78e021c02b9ca3b3a33215236e86f4e1ca50385662 | — | |
hash426f9ac9f873c9e7d316065b5cac39e0027a9c9dec21b3b96b6db345e196cd89 | — | |
hash43594723a67f6fcabc0f7555adb7df9a0487df1873b9669a8d977d1bf385e12a | — | |
hash43970535ad69ef05fcc3c5318f4e2b2bb92eddcbb029b9bd6fd79a652be94c5d | — | |
hash492a132deb06232d73b2830633aae721062898caf5b95864b4fa1c0a823b06ff | — | |
hash4e27035796c6bf7c88758af2370acb3e0ec98d1b84d3f19f34336df0af8bc067 | — | |
hash4f76ebd328ac11b5a3228ab52434ce57d46e436dc76c3c25a4b45e3cf046cdeb | — | |
hash4fc0a3ba8be36fbeeb31b0b4a250ce9a1d0bfc2110d2180d4d3f96e4d0e87c93 | — | |
hash51678577b43986cdcfc5fedd47cee5bc007221c7ee2fc2bc94b1b19317a6c055 | — | |
hash557a278750174d4ae058a7e11febd28e3c296c801e5ef319a1e0be9497093489 | — | |
hash56c4afbd4d99698eaf1efaa0d6654c5969fdf893072b39e6e301a60b25a91996 | — | |
hash578a2d1f389adb6b514a8491e771db100ef5e13a9b9dc5bcb57d1e83dcbef0fd | — | |
hash59900f715ba9704963b403b46518bf9acdcabcb76472066a2479dfe8c00e02b0 | — | |
hash5e39dfab5879138ce94d2f6918679f7e69c8ee50715d4bc48e0f0f20dab21c34 | — | |
hash60bd3b2945a04bf99fd7ab801e47f8b1372c03dbd3f168b7eec12e0c057f6e38 | — | |
hash639830080e6efdb718ec5aeb4e03c5e7721246919dba066effd1d1280a13962d | — | |
hash64f2d69a665b77c16569c0c28e3ceb8a061c0b1d9ec306b89fc7deddaf55bbe6 | — | |
hash68c142aecd006c86c0f28a8662bee5f7b94beeeac27b8e356901fb8ac0425b59 | — | |
hash6b79afe0b533307cd0ec396655131c7f49e8c480de04b6cdca2e0f1353968040 | — | |
hash6d80ae4403f6813bc9acd49729548b92759f0198ffbff0e4c295d7df660f4fd3 | — | |
hash6d8cba92107b8d1ac72052bfc9326bebcb24ee75b0fc3bb6d890cec5e9ab380a | — | |
hash6e7244523e8b853c4bc3dd655f5dd40b59fee0b9e1fa70c8bf829dee315d731e | — | |
hash6f641749f3d85c9693f126e05eb426d55e986d180ebd9a6e84dbf10a4b568a19 | — | |
hash712332746cf76edb6deaa49b59662e505a2b9f366226e9b0e020e85dda90d9ff | — | |
hash714e7f13188d618d80698e909e1a7bcc80cfc073fc84dc7762062c134490dcab | — | |
hash72f149969ef2173dc29d436135d5ce39adcc82fca1b3a7abae66150d95af6035 | — | |
hash7409846a292d79be09911952ef795a1a56e5064ee03d4da3025c09df51a19e4d | — | |
hash75798ec92779e8af81de5906c6f35dffd8bbabe741e8ac821887924be2a079ff | — | |
hash776df17dcfb99b5cc06d1ff75528955ca51b5f6d115ec4e6ff0151fff4190c30 | — | |
hash7982c897c5bc8f3b31fc610b9cada477c8a8b66138aa5dba47ea6526152318ac | — | |
hash79b608e1a1c8d3f839ef31dd94eae3526f69a9298c8d9f2f86d9050e77232d4b | — | |
hash79e0231d25d7588fa17037f64b69d85c08940b5fe3b7672a4366c9e012d353b8 | — | |
hash7d4c946027003c720a3ec8c357b8cd4ca821e950876f06b1cb5bef9df2118dc9 | — | |
hash7ea73c32040727b17ed265fb4a3f9b2cc314a97665b5d707d43adc0391e80915 | — | |
hash7ee145ad0db7184704b3d1dba4d8399d1803424a02d621229cc895b467a1550b | — | |
hash809eb1c5776d97da66b6ccf8df655aed555f1bff42dca18f8a7fdbc90a528ccb | — | |
hash80ec9992a61fa47f222ed879bd7f948d321e27517ce3c08231e48127ac6dca39 | — | |
hash828a1a643102009be7c236bc29789972b3c3cf10a8638bf0baaf1f009684369d | — | |
hash844edd67c98220c02ebce13a83dae14e9f01077916e61c5c658550524eb374bd | — | |
hash888537d9a0d0983584f335eb4abcc1cccbbc653e5424b00b14d5b885f0995b85 | — | |
hash8ac670705f940ab1edb850331595f8b4ac906678fd63e4ab8fae03975420de44 | — | |
hash8be0af109d3f166ea7ca3968963c9ef01a6441bb941b1399f2bf8f3902dbfce2 | — | |
hash8c85425368d710441baaafea617480367f28bc26a54899568c4d62ecaeb65021 | — | |
hash8d96d0d7a8d6b0717e6f75f60a3889e86a4203aa8aab0e9349b70e38ad8ddf8f | — | |
hash8e19cd717704dd9907491a69505d5920208fb94506f7f0b9404d24adbb430625 | — | |
hash91e18fc48a0ee20c62ccc955f4aa401ec4080f2f47da99a1ffc381af888c4b17 | — | |
hash937e75558fede0ab3a043c022e61aac840493ca7335166a320646598266eb2ba | — | |
hash93e642fbe2bd6e1da0e7d17c843c647ab01b7f2484396bbf007f73d34ff4ea41 | — | |
hash977c1ba6fe57f66b24df90039b6f6af4587ef4b1672bfb6035f612fd1cf7fbd1 | — | |
hash9b6430da65a521fa76b3d4702a70974b913420fdc1e327547600606b80ba64d2 | — | |
hash9bf6fa1f35a73e5665e0cf8512e576a0f5cb99af31d05ee0640a74de960bb38c | — | |
hash9da8e036443eebab49e86d4f605260a18b44dd1e0ee6cde6736dd942203a74cd | — | |
hash9e2ad1d34fb87a26f99895466d4cb81b879d3540efa03ebdad1a40d4117646a2 | — | |
hash9e5539de48ed2120dec5f3382c3675fb6cfcfa6e4fb11cc9b9785cc584dbfa39 | — | |
hasha0a88b64b05c0ecdb12d41fcc4e19d1cdd09ebac70be571a7ad8e50c50bd2d7e | — | |
hasha2b09bc35afdd001d708897e29c26f531b7c5384606bb523535339f93452f1ce | — | |
hasha6bc4f4f62999fb8f8d04befc96677abf786b8f5ecda7ad4bd59ed94abf09297 | — | |
hasha770962691edc713ffbba74b855ae59bc32735a7e6524282a5a1f813e971a313 | — | |
hasha9d7504f012749ff50b12fee1e129eb676763355f836321822ab77b6fb7ef9ac | — | |
hashabad58d56f65025d6eef0bb5b6402f6e0f34463cc331dc0fe696472ab768f63f | — | |
hashb011de113a0ba863bb987f21b75b1ffa835f69c02a856a5b91c61b6a8549da2e | — | |
hashb2e6d7becd9a7bd1411118e179c28f5c96ae529cfba5f562a0384a5bd0c038e0 | — | |
hashb31b5644d5e88caa45941921d97c05696adefe884f11a946c9f00141d959caec | — | |
hashb3308c165e46332fe6a19ca222f4bda0d193b035b8dc1c2135a4005d7d65864c | — | |
hashb5542dd5d015d8a5b1405973d9dcf5a94dccdcc970f43b4197e5dbc2dff3028a | — | |
hashba38e037657db285c00c4e737c10c467908383c81e771b75ee039b1b8e595f4b | — | |
hashbc264399a8d894ba8baf6861c16a17df91935895b3a44c401654787ee78fddd0 | — | |
hashbeeb2632662a2c4088e6df90788b290948717b192c0bbe1e9ba3e9390ff5dbd0 | — | |
hashbf3d9bb02996a45e1e7e0b89dae32a6fc5faceb413d8bbbfca35889078bd7a96 | — | |
hashc0a86bee959f299518129d3220f5a2cb2a2d74ccce80586ce4db5f5215b97c94 | — | |
hashc0fdb5ae93508123a0ccb87d470ef12a1a6048592bb3e67855335c79a60e138c | — | |
hashc34baac5ee3212c7acbc4b3a7b2a27336f1c693327c675a5e4e4b822f964d801 | — | |
hashc640b4d8201c8a738d50f7cc8f842a4875ff24c5440f152cecce4af99f3ddbdd | — | |
hashca33271f15d966b2da95010748d62e5e72c4783c74715953e4f79264cde54cef | — | |
hashcb43b4165208d878c1bbd39a6e45de1efa3cda9f334c5bfb4e9adf59b55a976b | — | |
hashcc73a3d2fc03fc38c58f27d98274680eb84b77fc4ad6dd424f88984effa2d1bb | — | |
hashcc97fd7febd8ddce86ac7685a10c060346e1aec7059f2dcfbdc56ec415db7a8e | — | |
hashccf4d4142892222f1f7d6c196338065ae55e3296f03bb8875345f6fd485917ef | — | |
hashcec5ccc08f96fa9fa697f7d146283566b31c1a322276bc56d47617d31889b424 | — | |
hashd36a4b75a39c59382d4f96b119849d1151ecd68b409c846a551f0b2d47ef1949 | — | |
hashd49677515a17747af85c703ae62f36ce5a8bdb80056e6f3b3057f4380866cbea | — | |
hashd80fbf09bd877c73e6e934af66176b23e9ff9843b110936b6ad5bffbd849bce9 | — | |
hashdc6d9730a652a7b39b636cb3ee50b6d5fa04e3882a1f4078048968928f96fa6e | — | |
hashdeb65779808d584ec755e8cb6a78f8df7fe8105d80e454a0763d34f6c49a893f | — | |
hashe16902ef4070386cd90dd7d66ebe1fe90f94f532bc547152fb24cf9f92c1ef77 | — | |
hashe269d4d75f3c05b2b86b924251d7107c635cce57f6aea83d518921eccf04b57b | — | |
hashe3fe38399beafd74c35c9dc9350df9cf4be40be2378cfc4b915afee5d417bd8e | — | |
hashe7923de87700df0de640ef2499a8dd9d86f0f000e98bd3242efbe8b96b6e61b6 | — | |
hashe87fed756fb4ddf14405f4edf90a4c661c34c972d84d9ca7c0c762fae8b5f87f | — | |
hashe8fedceccca49458bfce4f4c3243460caf9d5d4341e63fd572d553a702a72c30 | — | |
hashe9d8e1c00faa8d4eb4af0f389da9165bcc99a1754b1eb58b5f6a235e33e03d4b | — | |
hashec8bb702cca9a92516f8474e708acbe6e1f4987adc8aac6c549d752397cec139 | — | |
hashefab8707fb01291ba00481145766260ec0a125394551c63b216da2d2daf50ebc | — | |
hashf03145e889d6098142a9872aab774643afcdb3a32535c0d5b3ce322eb0c3bab2 | — | |
hashf2fd583c9c9059bd3ca02df23384e1e5694675c63cb4852185db6ffd5ec1311d | — | |
hashf359a4067ef66ffa80a3000a60a30f2dd31a7eb8ec5b2df8579e609cfaf9728a | — | |
hashf459ff9867b08eb2a7b8f33eb97d6ad782ad9066cf316c5b584f264fbfd91291 | — | |
hashf71cda0b52b11c30fd34af51ea82b1c2fd13ab2fd0120cbf361dce34bffae73a | — | |
hashf822ec9f04aee7f29f93dbd6ab235ce92ba4446c2d0be52f7d9be64d8da30789 | — | |
hashf88a99d94b4bd5ac0f916e8128ad3735604531ee38e0731d672d5fc4f607e69e | — | |
hashfa2f7614462ef071aa4d7032128edce12889f7a677ce16c0a0a1ccc7e1c4fa5d | — | |
hashfb4a36fbdcf51c9847d94c0fcf8d62045a5ab781b7b1695eaed5b22f21d34ed9 | — | |
hashfda55c91ceb9524f1cc99ccfddcd287f1e1a8078b48ff86895905b18109a1cf4 | — | |
hashfe1f2d47ee0ab4c27f10487643d4f956057af31e989fa39e9a8686a6fdbc633a | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://goolgepalay.com | — | |
urlhttp://tiktokgplya.sbs | — | |
urlhttps://bjsffsj.sbs | — | |
urlhttps://fantasy-hub.online | — | |
urlhttps://fantasy-hub.ru | — | |
urlhttps://telegramunlock.ru | — | |
urlhttps://tikitok-goolges.sbs | — | |
urlhttps://tikpremplaymarktuzb.sbs | — | |
urlhttps://tiktoki-goolge.sbs | — | |
urlhttps://unlockk.play-google-store.ru | — | |
urlhttps://wildberries.play-market-com.online | — | |
urlhttps://www.tikitok-playgoolge.sbs | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbjsffsj.sbs | — | |
domainfantasy-hub.online | — | |
domainfantasy-hub.ru | — | |
domaingoolgepalay.com | — | |
domaintelegramunlock.ru | — | |
domaintikitok-goolges.sbs | — | |
domaintikpremplaymarktuzb.sbs | — | |
domaintiktokgplya.sbs | — | |
domaintiktoki-goolge.sbs | — | |
domainunlockk.play-google-store.ru | — | |
domainwildberries.play-market-com.online | — | |
domainwww.tikitok-playgoolge.sbs | — |
Threat ID: 6911d19153b42a4b74ce7a02
Added to database: 11/10/2025, 11:50:41 AM
Last enriched: 11/10/2025, 12:05:30 PM
Last updated: 11/10/2025, 1:32:56 PM
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
Nine NuGet packages disrupt DBs and industrial systems with time-delayed payloads
MediumGlassWorm Malware Returns to Open VSX, Emerges on GitHub
MediumLazarus Group targets Aerospace and Defense with new Comebacker variant
MediumWatch out for SVG files booby-trapped with malware
MediumFrom primitive crypto theft to sophisticated AI-based deception
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.