The Video That Plays You: Fake MP4 File Carries Malicious Payload
ID: 958e9527-b108-5795-8a1d-7dba07b9fcbd
STIX ID: report--958e9527-b108-5795-8a1d-7dba07b9fcbd
Feed Name: Censys Blog
Censys ARC observed an active multi-stage delivery chain that serves raw PowerShell droppers and a fake MP4 carrier (containing an XOR key and compressed PowerShell in an ISO-BMFF uuid box) from Cloudflare-fronted and direct hosts; the chain decrypts and executes a NetSupport Manager client configured for silent operation and connects to WebSocket-based C2 gateways. The report documents 18 distinct builds across ~40 live stage-1 endpoints, lists carrier URLs, payload and dropped-file hashes, persistence markers (SecurityHealth Run key, ProgramData run-once marker), and detection/mitigation insights for identifying anomalous MP4 carriers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
