home.social

#malspam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malspam, aggregated by home.social.

fetched live
  1. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  2. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  3. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  4. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  5. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  6. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  7. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  8. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  9. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  10. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  11. A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  12. A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  13. A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  14. A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  15. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  16. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  17. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  18. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  19. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  20. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  21. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  22. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  23. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  24. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  25. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  26. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  27. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  28. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  29. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  30. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  31. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  32. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  33. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  34. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  35. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  36. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  37. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  38. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  39. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  40. A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  41. A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  42. A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  43. A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  44. New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.

    Threat vectors observed:
    • Brand impersonation campaigns
    • AI-generated dating personas
    • Advance-fee survey funnels
    • Delivery notification phishing
    • Pharma spam distribution
    • Healthcare provider impersonation (e.g., Techniker Krankenkasse)
    Geographic targeting concentrated in the U.S. (55%) and key European markets.

    Question for defenders:
    Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
    Engage below.

    Follow @technadu for threat intelligence reporting.

    #ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk

  45. New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.

    Threat vectors observed:
    • Brand impersonation campaigns
    • AI-generated dating personas
    • Advance-fee survey funnels
    • Delivery notification phishing
    • Pharma spam distribution
    • Healthcare provider impersonation (e.g., Techniker Krankenkasse)
    Geographic targeting concentrated in the U.S. (55%) and key European markets.

    Question for defenders:
    Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
    Engage below.

    Follow @technadu for threat intelligence reporting.

    #ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk

  46. New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.

    Threat vectors observed:
    • Brand impersonation campaigns
    • AI-generated dating personas
    • Advance-fee survey funnels
    • Delivery notification phishing
    • Pharma spam distribution
    • Healthcare provider impersonation (e.g., Techniker Krankenkasse)
    Geographic targeting concentrated in the U.S. (55%) and key European markets.

    Question for defenders:
    Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
    Engage below.

    Follow @technadu for threat intelligence reporting.

    #ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk

  47. New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.

    Threat vectors observed:
    • Brand impersonation campaigns
    • AI-generated dating personas
    • Advance-fee survey funnels
    • Delivery notification phishing
    • Pharma spam distribution
    • Healthcare provider impersonation (e.g., Techniker Krankenkasse)
    Geographic targeting concentrated in the U.S. (55%) and key European markets.

    Question for defenders:
    Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
    Engage below.

    Follow @technadu for threat intelligence reporting.

    #ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk

  48. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  49. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  50. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  51. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  52. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  53. If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
    app.any.run/tasks/a38ca435-f03

  54. If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
    app.any.run/tasks/a38ca435-f03

  55. If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
    app.any.run/tasks/a38ca435-f03