VT-get.activated.win
medium
📛 Threat Title
VirusTotal: get.activated.win
Description
VirusTotal verdict: 2 malicious / 3 suspicious of 91 engines.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
get.activated.win
VT 5 / 91
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
get.activated.win- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Submitted to VirusTotal for analysis.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Chong Lua Dao | malicious | malicious |
| VIPRE | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
| URLQuery | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP INC |
| TLD | win |
History
| Creation date | 2024-05-15 02:03 UTC |
| Last analysis | 2026-07-11 22:20 UTC |
| Last modified on VirusTotal | 2026-07-11 22:25 UTC |
| Last WHOIS update | 2026-05-18 19:46 UTC |
References (1)
-
VirusTotal report
VirusTotal verdict: 2 malicious / 3 suspicious of 91 engines.
Remediations (10)
-
web:any.run
Online sandbox report for https://get.activated.win, verdict: Malicious activity
-
web:bearyangry.com
A typosquatted domain, get.activate.win, mimicked Microsoft Activation Scripts (MAS) and was used to deliver malicious PowerShell scripts. The payload, Cosmali Loader, can spawn cryptomining utilities and the XWorm remote‑access trojan (RAT).
-
web:ethicalhackingnews.substack.com
Reinstalling Windows and exercising caution when using open-source software are recommended to avoid further infection. The malicious domain "get.activate [.]win" was used to spread PowerShell malware that infects systems with the 'Cosmali Loader'. The Cosmali Loader is a cryptomining utility and XWorm remote access trojan (RAT).
-
web:medium.com
Attackers registered the domain get. Activate [.]win, which looks almost identical to the legitimate get.activated.win — the only difference is the missing "d".
-
web:www.bleepingcomputer.com
A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the 'Cosmali Loader'.
-
web:www.joesandbox.com
Networking Uses ping.exe to check the status of other devices and networks Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\PING.EXE ping -4 -n 1 activated.win Detected non-DNS traffic on DNS port Source: global traffic TCP traffic: 192.168.2.16:56464 -> 1.1.1.1:53 Suricata IDS alerts with low severity for network traffic Source: Network traffic Suricata IDS: 1810000 ...
-
web:www.joesandbox.com
You are using Microsoft Internet Explorer. Therefore the report might not work properly.
-
web:www.reddit.com
If you are uncertain about MAS, you can do this--do the HWID activation, and wipe your computer and re-install Windows. Because the device is now activated by HWID, a new install should be automatically activated upon reinstall.
-
web:www.virustotal.com
2a:86:48:ce:3d:03:01:07:03:42:00:04:13:fe:16:
-
web:www.virustotal.com
b6:05:30:56:b6:82:41:62:d4:31:0b:79:c0:d4:e1:
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.