Observed arrival · 2026-10-05
A hidden-console PowerShell loader at goocloudcapf.com
Credibility concern recorded. The source reference remains available for verification and correction.
The homepage serves obfuscated PowerShell code that hides its console and reconstructs a Python-based payload.
- Worth noticing
- The PowerShell layer suppresses its console before assembling embedded Python code from base64-encoded text.
Field notes
The response contains executable PowerShell source instead of navigable site content: there are no links, headings, or controls in the extracted artifact. The script uses Windows API calls to hide its console, checks for a marker file in ProgramData, and assembles embedded Python code from base64 fragments. That code includes a remote-file retrieval routine and logic for extracting a UUID-associated block; the captured text ends before the complete execution path can be assessed.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue