Sample of the Week
Every week we publish one real scan from our own pipeline — not a demo, not a replay. These are live threats that behave differently depending on who is looking: a harmless page for datacenter scanners, the real payload for someone on a phone or a home connection. That gap is the whole point, and it is invisible to a single-vantage scanner.
Malware Cloaking 100% week of 2026-08-03
Target: uni***[.]click/Telegram_v12.8.3.apk
— deliberately redacted and defanged. Many hosts serving malware are themselves compromised small businesses; we publish the behaviour, never the name.
What each vantage was served
| Vantage | Result | Captured |
|---|---|---|
| Datacenter | Served a page | 35.2 KB |
| Residential | Served a page | 34.9 KB |
| Mobile | Served a page | 35.0 KB |
What it actually dropped
| SHA-256 | Type | Size |
|---|---|---|
6dcf0afacfe21c5e09267b5bfec917dc… |
payload · PowerShell/script · 5KB | 5.0 KB |
a5929754a9ddd1c3f2a31dbf491f6c0a… |
payload · PowerShell/script · 5KB | 5.0 KB |
Captured from the target itself — no second fetch that would tip off the operator. Samples are neutralized at rest, never served for download here, and confirmed-malicious ones are contributed to VirusTotal, MalwareBazaar and OTX so other defenders can block them.
Run this on your own URL
Every scan checks the same target from datacenter, residential and mobile vantages at once and reports what each one was served. The free scan covers the datacenter leg.
Scan a URL See what we’ve contributed
whack