{"id":15425,"date":"2026-06-05T04:49:35","date_gmt":"2026-06-05T04:49:35","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15425"},"modified":"2026-06-05T04:49:36","modified_gmt":"2026-06-05T04:49:36","slug":"faux-ghidra-dnspy-spiderfoot-websites-used-to-unfold-malware","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15425","title":{"rendered":"Faux Ghidra, dnSpy &#038; SpiderFoot Websites Used to Unfold Malware"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">Hackers are abusing search outcomes and professional-looking faux obtain portals to distribute malware by impersonating common safety instruments like Ghidra, dnSpy, and SpiderFoot. <\/p>\n<p class=\"wp-block-paragraph\">These websites seize customers\u2019 first click on on a \u201cObtain\u201d button and silently hand it to a site visitors distribution system (TDS) that may route victims to infostealers, clippers, and a classy loader framework dubbed \u201cSessionGate\u201d.<\/p>\n<p class=\"wp-block-paragraph\">These lookalike portals are well-designed, typically reference actual <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/github-strengthens-npm-security\/\" type=\"post\" id=\"187298\" target=\"_blank\" rel=\"noreferrer noopener\">upstream assets reminiscent of GitHub<\/a>, and, in some instances, rank surprisingly excessive in search outcomes for associated queries.<\/p>\n<p class=\"wp-block-paragraph\">The core monetization and an infection logic doesn&#8217;t reside within the seen HTML however in a CloudFront\u2011hosted JavaScript staging layer embedded on the pages. <\/p>\n<p class=\"wp-block-paragraph\">When a consumer clicks what seems to be a respectable obtain hyperlink, this script can hijack the occasion and redirect the browser right into a TDS infrastructure that decides, per session, whether or not to serve benign software program, probably undesirable purposes (PUAs), or outright malware.<\/p>\n<p class=\"wp-block-paragraph\">The faux portals maintain the unique obtain href intact, typically pointing to respectable mission areas, so status-bar previews and informal inspection look regular. <\/p>\n<p class=\"wp-block-paragraph\">On the similar time, an injected CloudFront script intercepts the primary eligible click on through browser\u2011particular handlers (for instance, mousedown on Chrome and click on on Firefox) and replaces the navigation with a TDS-controlled URL, utilizing strategies like cached window: open, artificial clicks, and momentary clean tabs.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Checkpoint stated in a report shared with GBhackers<\/a>, uncovered a large-scale operation constructed round cloned web sites for open\u2011supply and freeware tasks, together with excessive\u2011belief instruments utilized by safety researchers reminiscent of Ghidra, dnSpy, and SpiderFoot. <\/p>\n<p class=\"wp-block-paragraph\">Routing choices are stateful and gated by localStorage and anti-bot logic, which means solely the primary click on could also be malicious whereas repeated makes an attempt fall again to the seen, respectable hyperlink, making a reproducibility entice for analysts. <\/p>\n<p class=\"wp-block-paragraph\">The TDS then followers out by way of a number of redirectors and content material lockers, with branches that may finish in affiliate installs of respectable software program, PUA bundles, or malware payloads. <\/p>\n<p class=\"wp-block-paragraph\">Recognized entry domains embody impersonations reminiscent of ghidralite.com and dnspy.org amongst greater than 100 energetic websites embedding the identical marketing campaign scripts.<\/p>\n<p class=\"wp-block-paragraph\">Downstream of this TDS stack, researchers noticed a number of malware households, together with RemusStealer, AnimateClipper, and a beforehand unknown framework named SessionGate. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"760\" height=\"457\" src=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136.png\" alt=\"Fake Ghidra project website in Google search results (Source : Checkpoint).\" class=\"wp-image-188385\" srcset=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136.png 760w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136-300x180.png 300w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136-698x420.png 698w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136-150x90.png 150w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185136-696x419.png 696w\" sizes=\"(max-width: 760px) 100vw, 760px\"\/><figcaption class=\"wp-element-caption\">Faux Ghidra mission web site in Google search outcomes (Supply : Checkpoint).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">SessionGate stands out as a multi\u2011stage loader chain delivered through brief\u2011lived, per\u2011shopper URLs from Amazon S3 buckets, fronted by obfuscated JavaScript that validates the sufferer earlier than permitting entry to the Home windows executable.<\/p>\n<p class=\"wp-block-paragraph\">The SessionGate <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/multiple-7-zip-vulnerabilities-arbitrary-code-execution\/\" type=\"post\" id=\"187399\" target=\"_blank\" rel=\"noreferrer noopener\">loader embeds a 7\u2011Zip<\/a> SFX archive and may pivot to a benign installer UI when gating circumstances are usually not met, whereas closely obfuscated code, junk directions, and encrypted strings frustrate static evaluation. <\/p>\n<p class=\"wp-block-paragraph\">It performs in depth atmosphere and AV checks, contacts devoted C2 infrastructure with signed requests, and makes use of a two\u2011DLL structure the place the primary DLL acts as a \u201ckey dealer\u201d to derive one\u2011time decryption keys for the second, core payload module. <\/p>\n<p class=\"wp-block-paragraph\">The decrypted module behaves as a server\u2011pushed installer framework able to silently downloading and executing further software program, making it a versatile supply automobile for future malware.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"753\" height=\"335\" src=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185332.png\" alt=\"&#10;Some of the observed redirect chains across the TDS infrastructure (Source : Checkpoint).\" class=\"wp-image-188387\" srcset=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185332.png 753w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185332-300x133.png 300w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185332-150x67.png 150w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185332-696x310.png 696w\" sizes=\"auto, (max-width: 753px) 100vw, 753px\"\/><figcaption class=\"wp-element-caption\">Among the noticed redirect chains throughout the TDS infrastructure (Supply : Checkpoint).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">In one other department, the TDS chain ends with a password\u2011protected archive that in the end launches RemusStealer, a MaaS infostealer marketed on underground boards. <\/p>\n<p class=\"wp-block-paragraph\">RemusStealer makes use of an encrypted tasking protocol to exfiltrate browser knowledge from Chromium and Firefox, together with cookies, passwords, and vault materials, and it particularly targets a whole bunch of browser extensions, with heavy deal with cryptocurrency wallets, password managers, and 2FA plugins.<\/p>\n<p class=\"wp-block-paragraph\">A 3rd department results in a ClickFix\u2011fashion phishing web page that methods victims into operating a malicious mshta\u2011primarily based downloader chain, which ends in a crypto\u2011clipper often called AnimateClipper. <\/p>\n<p class=\"wp-block-paragraph\">This clipper makes use of shellcode staged by way of a bundled Python atmosphere and resolves its C2 by querying a sensible contract on the BNB Sensible Chain testnet, then hijacks clipboard pockets addresses and swaps them for attacker-controlled wallets embedded within the binary.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"772\" height=\"318\" src=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536.png\" alt=\"Two landing pages observed delivering SessionGate samples  (Source : Checkpoint).\" class=\"wp-image-188389\" srcset=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536.png 772w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536-300x124.png 300w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536-768x316.png 768w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536-150x62.png 150w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-04-185536-696x287.png 696w\" sizes=\"auto, (max-width: 772px) 100vw, 772px\"\/><figcaption class=\"wp-element-caption\">\u00a0Two touchdown pages noticed delivering SessionGate samples  (Supply : Checkpoint).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Impersonating Ghidra, dnSpy, and SpiderFoot provides the operators entry to a very engaging sufferer profile: safety researchers, reverse engineers, and technically inclined customers who typically have elevated privileges and entry to delicate environments. <\/p>\n<p class=\"wp-block-paragraph\">The marketing campaign\u2019s scale, mirrored in hundreds of public VirusTotal submissions throughout associated samples, means that that is primarily a site visitors acquisition and monetization pipeline whose feeds are selectively offered or routed to malware distributors.<\/p>\n<p class=\"wp-block-paragraph\">As a result of the faux portals carefully mimic respectable mission branding and protect actual repository hyperlinks, \u201chigh Google end result plus official\u2011trying web site\u201d is now not a dependable security sign. <\/p>\n<p class=\"wp-block-paragraph\">For defenders, this marketing campaign illustrates how TDS\u2011primarily based ecosystems blur the road between grey monetization and overt malware distribution, and why strict validation of obtain sources, DNS telemetry, and script\u2011degree behaviors is now vital even for well-known safety instruments.<\/p>\n<h2 id=\"h-iocs\" class=\"wp-block-heading\"><strong>IOCs<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Sort<\/th>\n<th>Indicator<\/th>\n<th><strong>D<\/strong>escription<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SHA-256<\/td>\n<td>598b023e56c45b19173e8f96c1c88036d732fec305cf6bf1b9cf4dbe304beb7f<\/td>\n<td>SessionGate Stage 1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>74091f5a8746a1c68d73e1fc1e4e1ff514632ee3f632a8b306f35dabae2d2b64<\/td>\n<td>SessionGate Stage 1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>15e6df0c95f2147952308e640d55270e9d097639eaebb34d4b352415f1c6bceb<\/td>\n<td>SessionGate Stage 1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>3bb92771e287aa0a8bdd8e5b5bb697427223eaefded3d9b64b5d5c32ad40f3c2<\/td>\n<td>SessionGate Stage 1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>cbad672d9bd06ce91ce465d049e50696fbaec9d209ca0ab1fd814d993d04bc9b<\/td>\n<td>SessionGate Stage 1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>4cdb1f7ac502289119f7f8256f00baaa994e6ecfb4000dcf5e1c46073508fcb3<\/td>\n<td>SessionGate Stage 2<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>cbad672d9bd06ce91ce465d049e50696fbaec9d209ca0ab1fd814d993d04bc9b<\/td>\n<td>SessionGate Stage 2 DLL #1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>ce0888df5e28716432013a8ae002437bd3e993fbe8362c5ff9efbddabfe0ab77<\/td>\n<td>SessionGate Stage 2 DLL #1<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>26f2abfc254a59c2386dd46dca16744f7147a0f0366cb6008e1d53219175f44c<\/td>\n<td>SessionGate Stage 2 DLL #2<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>e6a1a428a7c09c9946f7c0179d89b263f442dc3208b5144a9146c200e4185bd6<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>87361ba2bb412dcf49f8738f3b8b9b7dccb557ad2e76ea8d98ffa5b098ae3886<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>39dc2327fe1e5a56ac5ad9dc02f0386cff3d83dcfdc558cacba42ebb9dcc5ec2<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>2e842eab0c16ddd1a2ec4a56610adb58d115b65a1e08e9b67e7e375f8eed0873<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>appfreshstart[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>appgetonline[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>webinnosetup[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>appmakingcenter[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>yourfastcrc[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>mobileversioncrc[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>webcrcprove[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>integritycrc[.]com<\/td>\n<td>SessionGate<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/buccstanor[.]pics:28313<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/baxe[.]pics:48261<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/217.156.122[.]75:1378<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/intem[.]lat:9592<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/ropea[.]high:28313<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/forestoaker[.]com:6290<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/buccstanor[.]pics:48261<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/94.231.205[.]229:28313<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/gluckcreek[.]on-line:48261<\/td>\n<td>RemusStealer<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/185.0xA1.0xFB[.]58\/navy.7z<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>http:\/\/194.150.220[.]218\/4SLEYpfAk57hGubo\/fo0suc2ki2.rtf<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/cdn-1415.brightcanvas[.]digital\/fo0suc2ki2.rtf<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>kr.hugo-lapp[.]co<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>io.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>cw.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>st.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>td.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>fd.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>ed.hugo-lapp[.]lat<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>flame-guard[.]cc<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<tr>\n<td>Area<\/td>\n<td>carlessclapped[.]com<\/td>\n<td>AnimateClipper<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Word:<\/strong>\u00a0IP addresses and domains are deliberately defanged (e.g.,\u00a0<code>[.]<\/code>) to stop unintended decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms reminiscent of MISP, VirusTotal, or your SIEM.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Immediate Updates and Set GBH as a Most well-liked Supply in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Hackers are abusing search outcomes and professional-looking faux obtain portals to distribute malware by impersonating common safety instruments like Ghidra, dnSpy, and SpiderFoot. These websites seize customers\u2019 first click on on a \u201cObtain\u201d button and silently hand it to a site visitors distribution system (TDS) that may route victims to infostealers, clippers, and a classy [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15427,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9317,67,9316,216,1900,9318,1867],"class_list":["post-15425","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-dnspy","tag-fake","tag-ghidra","tag-malware","tag-sites","tag-spiderfoot","tag-spread"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15425"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15425\/revisions"}],"predecessor-version":[{"id":15426,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15425\/revisions\/15426"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15427"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-05 07:11:30 UTC -->