Back to Intelligence

NetSupport Manager RAT Hidden in Fake MP4 uuid Boxes: PowerShell Loader Campaign — OTX Detection Pack

SA
Security Arsenal Team
September 27, 2026
8 min read

Threat Summary

AlienVault OTX pulse "Fake MP4 File Carries Malicious Payload" (TLP:WHITE, modified 2026-09-28, sourced from Censys research) documents a sophisticated infection chain delivering the NetSupport Manager remote access trojan (RAT). The campaign is unattributed but operationally consistent with initial-access brokers (IABs) that stage commodity RATs for follow-on ransomware or data theft operations.

The kill chain is notable for its abuse of legitimate file-format mechanics:

  1. Delivery — Victims are lured to download what appears to be an MP4 video file, served from attacker infrastructure fronted by Cloudflare to blend into legitimate CDN traffic.
  2. Container abuse — The MP4 file is structurally valid enough to pass naive file-type checks, but instead of playable video it contains approximately 6.5 MB of encrypted payload data inside ISO Base Media File Format (ISO-BMFF) uuid extension boxes — a legitimate container feature designed for vendor-specific metadata, here repurposed as a covert payload carrier.
  3. Loader — A PowerShell loader retrieves and parses the fake MP4, extracts and decrypts the encrypted blob from the uuid boxes, and executes the NetSupport client in memory or drops it to disk.
  4. C2 / RAT activation — NetSupport Manager establishes remote administrative control, giving the operator full desktop access, file transfer, and command execution capabilities.

Objective: Persistent remote access to victim endpoints — the classic precursor to lateral movement, credential harvesting, and either ransomware deployment or sale of access on dark web markets. NetSupport Manager remains one of the most-abused legitimate RMM tools in the criminal ecosystem precisely because its signed binaries evade many signature-based controls.

Threat Actor / Malware Profile

Malware Family: NetSupport Manager (abused legitimate RMM) Attribution: Unknown actor; TTP overlap with NetSupport distribution campaigns historically linked to SocGholish-adjacent and IAB ecosystems.

Distribution method: Fake MP4 media files hosted on attacker-controlled domains (e.g., approvalrequest-api.com/333.mp4, direct-IP hosting at 89.34.90.111/tzast.mp4). Delivery is likely via drive-by download, malvertising, or phishing links masquerading as video content. Cloudflare fronting provides TLS legitimacy and infrastructure agility.

Payload behavior: The encrypted blob (~6.5 MB) embedded in the MP4's uuid extension boxes decrypts to a NetSupport Manager client (client32.exe and associated DLLs such as PCICL32.dll, HTCTL32.dll). Once active, the operator gains full interactive remote control.

C2 communication: NetSupport clients beacon to operator gateways, historically over TCP ports 5405 (default) and 443, using the tool's proprietary protocol. In this campaign, staging infrastructure includes x2664.com, usersecuritycheck.com, approvalrequest-api.com, and karlenagida.com.

Persistence mechanism: NetSupport drops commonly establish persistence via:

  • Registry Run keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run with values pointing at client32.exe
  • Installation under user-writable paths: %APPDATA%, %LOCALAPPDATA%, %ProgramData%, or %TEMP% subdirectories
  • Occasionally scheduled tasks masquerading as update jobs

Anti-analysis techniques:

  • Format smuggling — payload hidden in ISO-BMFF uuid boxes defeats file-type validation, static AV scanning of the carrier file, and many sandbox detonation paths that treat MP4s as benign media
  • Encryption — the 6.5 MB blob is encrypted; the decryption key/logic lives in the PowerShell loader, splitting the kill chain across artifacts
  • Cloudflare fronting — C2 and staging resolve to Cloudflare IPs, defeating IP-reputation blocking and complicating attribution
  • Living-off-the-land — PowerShell is the only obviously malicious stage prior to the signed NetSupport binary executing

IOC Analysis

The pulse carries 64 indicators across two observable types:

Domains (4 malicious + 1 reference): x2664.com, usersecuritycheck.com, approvalrequest-api.com, karlenagida.com (censys.com is the research reference — exclude from blocklists).

URLs: http://89.34.90.111/tzast.mp4 and http://approvalrequest-api.com/333.mp4 — payload staging locations serving the fake MP4 containers. The direct-IP URL pattern (89.34.90.111) is high-fidelity: legitimate business workflows rarely pull MP4 media over raw HTTP from bare IPs.

Operationalization guidance for SOC teams:

  • Block at proxy/DNS: Add all four domains and the IP to egress filtering, DNS sinkholes, and SWG blocklists. Treat any HTTP request for a .mp4 from a non-media domain as suspicious.
  • Retro-hunt: Query 90 days of proxy, DNS, and firewall logs for these indicators — initial access may predate the pulse publication.
  • Pivot tooling: Censys and Shodan for infrastructure pivots on the hosting IPs; VirusTotal/OTX for related samples; mp4dump (Bento4) or ffprobe locally to inspect MP4 box structure for anomalous uuid boxes carrying megabytes of data.
  • Detection content: The uuid-box smuggling technique is the durable signal — infrastructure will rotate, but a PowerShell process fetching .mp4 files and spawning unsigned child processes is a behavioral invariant.

Detection Engineering

YAML
---
title: PowerShell Downloading Suspicious Media File Payload
description: Detects PowerShell invoking web requests to retrieve .mp4 files, consistent with the fake MP4 NetSupport Manager staging chain observed in OTX pulse 'Fake MP4 File Carries Malicious Payload'
id: 8f2a1c4e-7b3d-4e5a-9c1f-2d6b8a4e5f01
status: experimental
author: Security Arsenal Threat Intel
references:
  - https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
  category: process_creation
  product: windows
detection:
  selection_process:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
  selection_download:
    CommandLine|contains:
      - 'Invoke-WebRequest'
      - 'Invoke-RestMethod'
      - 'DownloadFile'
      - 'DownloadString'
      - 'Start-BitsTransfer'
      - 'curl.exe'
      - 'wget'
  selection_mp4:
    CommandLine|contains:
      - '.mp4'
  condition: selection_process and selection_download and selection_mp4
falsepositives:
  - Legitimate media automation scripts (rare in enterprise endpoints)
level: high
tags:
  - attack.command_and_control
  - attack.t1105
  - attack.execution
  - attack.t1059.001
---
title: NetSupport Manager RAT Client Execution
description: Detects execution of NetSupport Manager client binaries or installation in user-writable directories, indicative of abused RMM deployment
date: 2026/09/28
id: 3b7d9e2a-5c1f-4a8b-8d3e-1f6a9c2b4d02
status: experimental
author: Security Arsenal Threat Intel
references:
  - https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
  category: process_creation
  product: windows
detection:
  selection_binary:
    - Image|endswith: '\client32.exe'
    - OriginalFileName: 'client32.exe'
    - Description|contains: 'NetSupport'
  selection_paths:
    Image|contains:
      - '\AppData\Roaming\'
      - '\AppData\Local\'
      - '\ProgramData\'
      - '\Temp\'
      - '\Users\Public\'
  condition: selection_binary or (selection_paths and 1 of selection_binary)
falsepositives:
  - Legitimate NetSupport Manager deployments by IT (verify against authorized RMM inventory)
level: high
tags:
  - attack.command_and_control
  - attack.t1219
  - attack.persistence
  - attack.t1543
---
title: Network Connection to Known Fake MP4 Staging Infrastructure
description: Detects network connections to domains and IP associated with the fake MP4 NetSupport Manager campaign staging and C2 infrastructure
date: 2026/09/28
id: 5e1c8a3b-9d4f-4b2c-7e6a-3b8d1f5a2c03
status: experimental
author: Security Arsenal Threat Intel
references:
  - https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
logsource:
  category: network_connection
  product: windows
detection:
  selection_domain:
    DestinationHostname:
      - 'x2664.com'
      - 'usersecuritycheck.com'
      - 'approvalrequest-api.com'
      - 'karlenagida.com'
  selection_ip:
    DestinationIp: '89.34.90.111'
  condition: selection_domain or selection_ip
falsepositives:
  - Unlikely; these indicators are campaign-specific
level: critical
tags:
  - attack.command_and_control
  - attack.t1071.001
KQL — Microsoft Sentinel / Defender
// Hunt: Fake MP4 NetSupport campaign — network IOCs + PowerShell staging behavior
let CampaignDomains = dynamic(["x2664.com","usersecuritycheck.com","approvalrequest-api.com","karlenagida.com"]);
let CampaignIPs = dynamic(["89.34.90.111"]);
let NetIOC = DeviceNetworkEvents
| where Timestamp > ago(90d)
| where RemoteUrl has_any (CampaignDomains)
   or RemoteIP in~ (CampaignIPs)
   or RemoteUrl endswith ".mp4" and RemoteUrl !has_any ("youtube","vimeo","microsoft","akamai","cloudfront")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort;
let PsLoader = DeviceProcessEvents
| where Timestamp > ago(90d)
| where FileName in~ ("powershell.exe","pwsh.exe")
| where ProcessCommandLine has_any ("Invoke-WebRequest","DownloadFile","Invoke-RestMethod","Start-BitsTransfer")
   and ProcessCommandLine has ".mp4"
| project Timestamp, DeviceName, ProcessCommandLine, InitiatingProcessFileName, AccountName;
union NetIOC, PsLoader
| sort by Timestamp desc
PowerShell
# NetSupport Manager RAT Hunt — Fake MP4 Campaign
# Run elevated across endpoints via your RMM/EDR or GPO startup script

$Report = @()

# 1. Known campaign IOC network connections
$IoCIPs = @("89.34.90.111")
$IoCDomains = @("x2664.com","usersecuritycheck.com","approvalrequest-api.com","karlenagida.com")
$conns = Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
    Where-Object { $IoCIPs -contains $_.RemoteAddress }
foreach ($c in $conns) {
    $proc = Get-Process -Id $c.OwningProcess -ErrorAction SilentlyContinue
    $Report += [pscustomobject]@{Type="IOC-Connection"; Detail="$($proc.ProcessName) -> $($c.RemoteAddress):$($c.RemotePort)"}
}

# 2. DNS cache check for campaign domains
$dns = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object {
    $n = $_.Entry; ($IoCDomains | Where-Object { $n -like "*$_*" }).Count -gt 0 }
foreach ($d in $dns) { $Report += [pscustomobject]@{Type="IOC-DNSCache"; Detail=$d.Entry} }

# 3. NetSupport binaries in user-writable paths
$suspectPaths = @("$env:APPDATA","$env:LOCALAPPDATA","C:\ProgramData","C:\Users\Public","$env:TEMP")
foreach ($p in $suspectPaths) {
    Get-ChildItem -Path $p -Recurse -Include "client32.exe","PCICL32.dll","HTCTL32.dll" -ErrorAction SilentlyContinue |
        ForEach-Object { $Report += [pscustomobject]@{Type="NetSupport-Binary"; Detail=$_.FullName} }
}

# 4. Persistence: Run keys referencing client32 or odd paths
$runKeys = @("HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
             "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run")
foreach ($rk in $runKeys) {
    (Get-ItemProperty -Path $rk -ErrorAction SilentlyContinue).PSObject.Properties |
        Where-Object { $_.Value -match "client32|\.mp4|AppData|ProgramData" -and $_.Name -notmatch "^PS" } |
        ForEach-Object { $Report += [pscustomobject]@{Type="Persistence-RunKey"; Detail="$rk :: $($_.Name)=$($_.Value)"} }
}

# 5. Scheduled tasks with suspicious PowerShell/mp4 references
Get-ScheduledTask -ErrorAction SilentlyContinue | ForEach-Object {
    $actions = ($_.Actions | Out-String)
    if ($actions -match "\.mp4|client32|DownloadFile|approvalrequest") {
        $Report += [pscustomobject]@{Type="Persistence-SchedTask"; Detail="$($_.TaskName): $actions"}
    }
}

if ($Report.Count -gt 0) { $Report | Format-Table -AutoSize; $Report | Export-Csv "C:\Temp\NetSupport_Hunt_$(hostname).csv" -NoTypeInformation }
else { Write-Output "[+] No NetSupport campaign artifacts found on $(hostname)" }

Response Priorities

Immediate (0–4h):

  • Block x2664.com, usersecuritycheck.com, approvalrequest-api.com, karlenagida.com, and 89.34.90.111 at DNS, proxy, and EDR network layers
  • Hunt 90 days retroactively with the KQL query above for both network IOCs and PowerShell .mp4 download behavior
  • Isolate any host showing established connections to campaign infrastructure; capture memory before remediation (PowerShell loader decryption logic may only exist in memory)

24h:

  • NetSupport Manager grants operators interactive access — assume credential exposure on any confirmed-compromised host. Force password resets for all users who authenticated on affected endpoints, revoke tokens/sessions, and review authentication logs for impossible travel and new MFA enrollments
  • Audit for lateral movement from confirmed hosts: SMB/RDP/WinRM connections outbound to other internal systems during the compromise window
  • Inventory authorized RMM tools; alert on any remote-access software not on the approved list

1 week:

  • Enforce PowerShell Constrained Language Mode or script-block logging + AMSI telemetry forwarding to the SIEM across the fleet
  • Implement application control (WDAC/AppLocker) blocking execution from user-writable paths and unsigned client32.exe instances
  • Configure the proxy to flag or block HTTP (non-TLS) downloads of media file types and direct-IP downloads
  • Add ISO-BMFF uuid-box anomaly detection to your sandbox/content-disarm pipeline: MP4s with multi-megabyte uuid boxes and no valid moov/media tracks should be quarantined

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.