Threat Summary
AlienVault OTX pulse "Fake MP4 File Carries Malicious Payload" (TLP:WHITE, modified 2026-09-28, sourced from Censys research) documents a sophisticated infection chain delivering the NetSupport Manager remote access trojan (RAT). The campaign is unattributed but operationally consistent with initial-access brokers (IABs) that stage commodity RATs for follow-on ransomware or data theft operations.
The kill chain is notable for its abuse of legitimate file-format mechanics:
- Delivery — Victims are lured to download what appears to be an MP4 video file, served from attacker infrastructure fronted by Cloudflare to blend into legitimate CDN traffic.
- Container abuse — The MP4 file is structurally valid enough to pass naive file-type checks, but instead of playable video it contains approximately 6.5 MB of encrypted payload data inside ISO Base Media File Format (ISO-BMFF)
uuidextension boxes — a legitimate container feature designed for vendor-specific metadata, here repurposed as a covert payload carrier. - Loader — A PowerShell loader retrieves and parses the fake MP4, extracts and decrypts the encrypted blob from the uuid boxes, and executes the NetSupport client in memory or drops it to disk.
- C2 / RAT activation — NetSupport Manager establishes remote administrative control, giving the operator full desktop access, file transfer, and command execution capabilities.
Objective: Persistent remote access to victim endpoints — the classic precursor to lateral movement, credential harvesting, and either ransomware deployment or sale of access on dark web markets. NetSupport Manager remains one of the most-abused legitimate RMM tools in the criminal ecosystem precisely because its signed binaries evade many signature-based controls.
Threat Actor / Malware Profile
Malware Family: NetSupport Manager (abused legitimate RMM) Attribution: Unknown actor; TTP overlap with NetSupport distribution campaigns historically linked to SocGholish-adjacent and IAB ecosystems.
Distribution method: Fake MP4 media files hosted on attacker-controlled domains (e.g., approvalrequest-api.com/333.mp4, direct-IP hosting at 89.34.90.111/tzast.mp4). Delivery is likely via drive-by download, malvertising, or phishing links masquerading as video content. Cloudflare fronting provides TLS legitimacy and infrastructure agility.
Payload behavior: The encrypted blob (~6.5 MB) embedded in the MP4's uuid extension boxes decrypts to a NetSupport Manager client (client32.exe and associated DLLs such as PCICL32.dll, HTCTL32.dll). Once active, the operator gains full interactive remote control.
C2 communication: NetSupport clients beacon to operator gateways, historically over TCP ports 5405 (default) and 443, using the tool's proprietary protocol. In this campaign, staging infrastructure includes x2664.com, usersecuritycheck.com, approvalrequest-api.com, and karlenagida.com.
Persistence mechanism: NetSupport drops commonly establish persistence via:
- Registry Run keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Runwith values pointing atclient32.exe - Installation under user-writable paths:
%APPDATA%,%LOCALAPPDATA%,%ProgramData%, or%TEMP%subdirectories - Occasionally scheduled tasks masquerading as update jobs
Anti-analysis techniques:
- Format smuggling — payload hidden in ISO-BMFF uuid boxes defeats file-type validation, static AV scanning of the carrier file, and many sandbox detonation paths that treat MP4s as benign media
- Encryption — the 6.5 MB blob is encrypted; the decryption key/logic lives in the PowerShell loader, splitting the kill chain across artifacts
- Cloudflare fronting — C2 and staging resolve to Cloudflare IPs, defeating IP-reputation blocking and complicating attribution
- Living-off-the-land — PowerShell is the only obviously malicious stage prior to the signed NetSupport binary executing
IOC Analysis
The pulse carries 64 indicators across two observable types:
Domains (4 malicious + 1 reference): x2664.com, usersecuritycheck.com, approvalrequest-api.com, karlenagida.com (censys.com is the research reference — exclude from blocklists).
URLs: http://89.34.90.111/tzast.mp4 and http://approvalrequest-api.com/333.mp4 — payload staging locations serving the fake MP4 containers. The direct-IP URL pattern (89.34.90.111) is high-fidelity: legitimate business workflows rarely pull MP4 media over raw HTTP from bare IPs.
Operationalization guidance for SOC teams:
- Block at proxy/DNS: Add all four domains and the IP to egress filtering, DNS sinkholes, and SWG blocklists. Treat any HTTP request for a
.mp4from a non-media domain as suspicious. - Retro-hunt: Query 90 days of proxy, DNS, and firewall logs for these indicators — initial access may predate the pulse publication.
- Pivot tooling: Censys and Shodan for infrastructure pivots on the hosting IPs; VirusTotal/OTX for related samples;
mp4dump(Bento4) orffprobelocally to inspect MP4 box structure for anomalous uuid boxes carrying megabytes of data. - Detection content: The uuid-box smuggling technique is the durable signal — infrastructure will rotate, but a PowerShell process fetching
.mp4files and spawning unsigned child processes is a behavioral invariant.
Detection Engineering
---
title: PowerShell Downloading Suspicious Media File Payload
description: Detects PowerShell invoking web requests to retrieve .mp4 files, consistent with the fake MP4 NetSupport Manager staging chain observed in OTX pulse 'Fake MP4 File Carries Malicious Payload'
id: 8f2a1c4e-7b3d-4e5a-9c1f-2d6b8a4e5f01
status: experimental
author: Security Arsenal Threat Intel
references:
- https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
category: process_creation
product: windows
detection:
selection_process:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
selection_download:
CommandLine|contains:
- 'Invoke-WebRequest'
- 'Invoke-RestMethod'
- 'DownloadFile'
- 'DownloadString'
- 'Start-BitsTransfer'
- 'curl.exe'
- 'wget'
selection_mp4:
CommandLine|contains:
- '.mp4'
condition: selection_process and selection_download and selection_mp4
falsepositives:
- Legitimate media automation scripts (rare in enterprise endpoints)
level: high
tags:
- attack.command_and_control
- attack.t1105
- attack.execution
- attack.t1059.001
---
title: NetSupport Manager RAT Client Execution
description: Detects execution of NetSupport Manager client binaries or installation in user-writable directories, indicative of abused RMM deployment
date: 2026/09/28
id: 3b7d9e2a-5c1f-4a8b-8d3e-1f6a9c2b4d02
status: experimental
author: Security Arsenal Threat Intel
references:
- https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
category: process_creation
product: windows
detection:
selection_binary:
- Image|endswith: '\client32.exe'
- OriginalFileName: 'client32.exe'
- Description|contains: 'NetSupport'
selection_paths:
Image|contains:
- '\AppData\Roaming\'
- '\AppData\Local\'
- '\ProgramData\'
- '\Temp\'
- '\Users\Public\'
condition: selection_binary or (selection_paths and 1 of selection_binary)
falsepositives:
- Legitimate NetSupport Manager deployments by IT (verify against authorized RMM inventory)
level: high
tags:
- attack.command_and_control
- attack.t1219
- attack.persistence
- attack.t1543
---
title: Network Connection to Known Fake MP4 Staging Infrastructure
description: Detects network connections to domains and IP associated with the fake MP4 NetSupport Manager campaign staging and C2 infrastructure
date: 2026/09/28
id: 5e1c8a3b-9d4f-4b2c-7e6a-3b8d1f5a2c03
status: experimental
author: Security Arsenal Threat Intel
references:
- https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
category: network_connection
product: windows
detection:
selection_domain:
DestinationHostname:
- 'x2664.com'
- 'usersecuritycheck.com'
- 'approvalrequest-api.com'
- 'karlenagida.com'
selection_ip:
DestinationIp: '89.34.90.111'
condition: selection_domain or selection_ip
falsepositives:
- Unlikely; these indicators are campaign-specific
level: critical
tags:
- attack.command_and_control
- attack.t1071.001
// Hunt: Fake MP4 NetSupport campaign — network IOCs + PowerShell staging behavior
let CampaignDomains = dynamic(["x2664.com","usersecuritycheck.com","approvalrequest-api.com","karlenagida.com"]);
let CampaignIPs = dynamic(["89.34.90.111"]);
let NetIOC = DeviceNetworkEvents
| where Timestamp > ago(90d)
| where RemoteUrl has_any (CampaignDomains)
or RemoteIP in~ (CampaignIPs)
or RemoteUrl endswith ".mp4" and RemoteUrl !has_any ("youtube","vimeo","microsoft","akamai","cloudfront")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort;
let PsLoader = DeviceProcessEvents
| where Timestamp > ago(90d)
| where FileName in~ ("powershell.exe","pwsh.exe")
| where ProcessCommandLine has_any ("Invoke-WebRequest","DownloadFile","Invoke-RestMethod","Start-BitsTransfer")
and ProcessCommandLine has ".mp4"
| project Timestamp, DeviceName, ProcessCommandLine, InitiatingProcessFileName, AccountName;
union NetIOC, PsLoader
| sort by Timestamp desc
# NetSupport Manager RAT Hunt — Fake MP4 Campaign
# Run elevated across endpoints via your RMM/EDR or GPO startup script
$Report = @()
# 1. Known campaign IOC network connections
$IoCIPs = @("89.34.90.111")
$IoCDomains = @("x2664.com","usersecuritycheck.com","approvalrequest-api.com","karlenagida.com")
$conns = Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
Where-Object { $IoCIPs -contains $_.RemoteAddress }
foreach ($c in $conns) {
$proc = Get-Process -Id $c.OwningProcess -ErrorAction SilentlyContinue
$Report += [pscustomobject]@{Type="IOC-Connection"; Detail="$($proc.ProcessName) -> $($c.RemoteAddress):$($c.RemotePort)"}
}
# 2. DNS cache check for campaign domains
$dns = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object {
$n = $_.Entry; ($IoCDomains | Where-Object { $n -like "*$_*" }).Count -gt 0 }
foreach ($d in $dns) { $Report += [pscustomobject]@{Type="IOC-DNSCache"; Detail=$d.Entry} }
# 3. NetSupport binaries in user-writable paths
$suspectPaths = @("$env:APPDATA","$env:LOCALAPPDATA","C:\ProgramData","C:\Users\Public","$env:TEMP")
foreach ($p in $suspectPaths) {
Get-ChildItem -Path $p -Recurse -Include "client32.exe","PCICL32.dll","HTCTL32.dll" -ErrorAction SilentlyContinue |
ForEach-Object { $Report += [pscustomobject]@{Type="NetSupport-Binary"; Detail=$_.FullName} }
}
# 4. Persistence: Run keys referencing client32 or odd paths
$runKeys = @("HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\Run")
foreach ($rk in $runKeys) {
(Get-ItemProperty -Path $rk -ErrorAction SilentlyContinue).PSObject.Properties |
Where-Object { $_.Value -match "client32|\.mp4|AppData|ProgramData" -and $_.Name -notmatch "^PS" } |
ForEach-Object { $Report += [pscustomobject]@{Type="Persistence-RunKey"; Detail="$rk :: $($_.Name)=$($_.Value)"} }
}
# 5. Scheduled tasks with suspicious PowerShell/mp4 references
Get-ScheduledTask -ErrorAction SilentlyContinue | ForEach-Object {
$actions = ($_.Actions | Out-String)
if ($actions -match "\.mp4|client32|DownloadFile|approvalrequest") {
$Report += [pscustomobject]@{Type="Persistence-SchedTask"; Detail="$($_.TaskName): $actions"}
}
}
if ($Report.Count -gt 0) { $Report | Format-Table -AutoSize; $Report | Export-Csv "C:\Temp\NetSupport_Hunt_$(hostname).csv" -NoTypeInformation }
else { Write-Output "[+] No NetSupport campaign artifacts found on $(hostname)" }
Response Priorities
Immediate (0–4h):
- Block
x2664.com,usersecuritycheck.com,approvalrequest-api.com,karlenagida.com, and89.34.90.111at DNS, proxy, and EDR network layers - Hunt 90 days retroactively with the KQL query above for both network IOCs and PowerShell
.mp4download behavior - Isolate any host showing established connections to campaign infrastructure; capture memory before remediation (PowerShell loader decryption logic may only exist in memory)
24h:
- NetSupport Manager grants operators interactive access — assume credential exposure on any confirmed-compromised host. Force password resets for all users who authenticated on affected endpoints, revoke tokens/sessions, and review authentication logs for impossible travel and new MFA enrollments
- Audit for lateral movement from confirmed hosts: SMB/RDP/WinRM connections outbound to other internal systems during the compromise window
- Inventory authorized RMM tools; alert on any remote-access software not on the approved list
1 week:
- Enforce PowerShell Constrained Language Mode or script-block logging + AMSI telemetry forwarding to the SIEM across the fleet
- Implement application control (WDAC/AppLocker) blocking execution from user-writable paths and unsigned
client32.exeinstances - Configure the proxy to flag or block HTTP (non-TLS) downloads of media file types and direct-IP downloads
- Add ISO-BMFF uuid-box anomaly detection to your sandbox/content-disarm pipeline: MP4s with multi-megabyte uuid boxes and no valid
moov/media tracks should be quarantined
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.