2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN PUSHES UNIDENTIFIED RATNOTICE:Zip files are 2026-7-31 20:54:0 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:34 收藏

2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN PUSHES UNIDENTIFIED RAT

NOTICE:

  • Zip files are password-protected.  Of note, this site has a new password scheme.  For the password, see the "about" page of this website.

ASSOCIATED FILES:

2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX PUSHES UNIDENTIFIED RAT

SMARTAPESG TRAFFIC LEADING TO FAKE CAPTCH/HUMAN VERIFICATION PAGE:

- https[:]//pewtercanto[.]top/user/throttle-effect.js
- https[:]//pewtercanto[.]top/user/throttle-effect.js
- https[:]//pewtercanto[.]top/user/acl-dom?JSMlAATp
- https[:]//pewtercanto[.]top/user/version-deploy.js?18c7713e5fb5a572

TRAFFIC GENERATED FROM RUNNING THE CLIPBOARD-INJECTED TEXT IN A RUN WINDOW:

- hxxp[:]//deltaode[.]com/po  <-- 302 redirect to HTTPS URL
- hxxps[:]//deltaode[.]com/po
- hxxp[:]//deltaode[.]com/wv  <-- 302 redirect to HTTPS URL
- hxxps[:]//deltaode[.]com/wv

INITIAL HTA FILE:

- SHA256 hash: e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832
- File size: 39,487 bytes
- File type: HTML document text, ASCII text, with very long lines (4879)
- File location: hxxps[:]//deltaode[.]compo
- File location: C:\Users\[username]\AppData\Local\ACER.xam
- File description: HTA file used to download malicious zip archive then extract and run the content

DOWNLOADED ZIP ARCHIVE:

- SHA256 hash: 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275
- File size: 13,991,507 bytes
- File type: Zip archive data, at least v2.0 to extract, compression method=deflate
- File location: hxxps[:]//deltaode[.]com/wv
- File location: C:\Users\[username]\Documents\553003097200721800\553003097200721800.pdf
- File description: File for legitimate program that uses DLL side-loading for an undentified RAT

POST-INFECTION TRAFFIC FROM UNIDENTIFIED RAT:

- TCP port 443 - dns[.]google - secure DNS query (not malicious)
- 89.124.79[.]98 port 443 - encoded or otherwise encrypted TCP traffic to C2 server for unidentified RAT

IMAGES


Shown above: SmartApeSG script injected into page from legitimate but compromised website.


Shown above: Fake CAPTCHA (human verification) page showing ClickFix instructions pasted into a run Window.


Shown above: Traffic from the infection filtered in Wireshark.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2026/07/31/index.html
如有侵权请联系:admin#unsafe.sh