Sample of the Week

Every week we publish one real scan from our own pipeline — not a demo, not a replay. These are live threats that behave differently depending on who is looking: a harmless page for datacenter scanners, the real payload for someone on a phone or a home connection. That gap is the whole point, and it is invisible to a single-vantage scanner.

Malware Cloaking 100%  week of 2026-08-03

Target: uni***[.]click/Telegram_v12.8.3.apk — deliberately redacted and defanged. Many hosts serving malware are themselves compromised small businesses; we publish the behaviour, never the name.

What each vantage was served

VantageResultCaptured
Datacenter Served a page 35.2 KB
Residential Served a page 34.9 KB
Mobile Served a page 35.0 KB

What it actually dropped

SHA-256TypeSize
6dcf0afacfe21c5e09267b5bfec917dc… payload · PowerShell/script · 5KB 5.0 KB
a5929754a9ddd1c3f2a31dbf491f6c0a… payload · PowerShell/script · 5KB 5.0 KB

Captured from the target itself — no second fetch that would tip off the operator. Samples are neutralized at rest, never served for download here, and confirmed-malicious ones are contributed to VirusTotal, MalwareBazaar and OTX so other defenders can block them.

Run this on your own URL

Every scan checks the same target from datacenter, residential and mobile vantages at once and reports what each one was served. The free scan covers the datacenter leg.

Scan a URL See what we’ve contributed