2026-08-21: SmartApeSG ClickFix campaign leads to two RATs
2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATSNOTES:Zip files are passwo 2026-8-21 17:49:0 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:4 收藏

2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS

NOTES:

  • Zip files are password-protected.  Of note, this site has a new password scheme.  For the password, see the "about" page of this website.

ASSOCIATED FILE:

2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS

TRAFFIC TO SMARTAPESG DOMAIN FOR FAKE CAPTCHA/VERFICIATION PAGE:

- hxxps[:]//rowanportico[.]global/identity/realm-xml.js
- hxxps[:]//rowanportico[.]global/identity/role-template?xPM7XYCZ
- hxxps[:]//rowanportico[.]global/identity/secure-theme.js?18cddb5baf41fce0

URLS GENERATED BY RUNNING THE CLICKFIX TEXT:

- hxxp[:]//lagoonandledger[.]com/crol  <-- 302 redirect to HTTPS URL
- hxxps[:]//lagoonandledger[.]com/crol
- hxxp[:]//lagoonandledger[.]com/sepc  <-- 302 redirect to HTTPS URL
- hxxps[:]//lagoonandledger[.]com/sepc

POST-INFECTION TRAFFIC GENERATED BY THE INITIAL RAT:

- dns[.]google:443 - legitimate domain, likely used for DNS by the initial RAT
- 144.124.242[.]171:443 - encoded or otherwise encrypted TCP traffic (not HTTPS/TLS)

POST-INFECTION TRAFFIC CAUSED BY THE FOLLOW-UP RAT:

- hxxp[:]//5.252.177[.]69/  <- multiple HTTP POST requests over TCP port 80

ARTIFACTS FROM AN INFECTED WINDOWS HOST:

- C:\Users\[username]\AppData\Local\WERCCC.hta 
  -- File description: Initial download after running ClickFix text
- C:\Users\[username]\Documents\217417970796890430\217417970796890430.pdf
  -- File description: Zip archive containing files for legitimate program that side-loads DLL for initial RAT
- C:\Users\[username]\AppData\Local\setup.exe
  -- File description: Installer for follow-up RAT
- C:\ProgramData\872413f495df78d2a39228e6c9219ae7\
  -- Location description: Directory containing files for legitimate program that side-loads DLL for follow-up RAT

SHA256 HASHES:

- da2d68e10ea89c520623df66cb1b942914514cada6eb9720b5af9bd1fca502a5 - WERCCC.hta
- c99ddd0ba299b3e2c8e7d418e692fee6fa3ce773c24fb4b2e80aa6543e1f2f76 - 217417970796890430.pdf
- 883dce16fd4939efbd1296b8984ca67284a23503c9e63f43693f09c4aa5bad62 - setup.exe

REGISTRY UPDATE FOR PERSISTENCE OF INITIAL RAT:

Key Name:          HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Class Name:        
Last Write Time:   8/21/2026 - 3:29 PM

Value 0
  Name:            VAS Advanced Broker
  Type:            REG_SZ
  Data:            C:\Users\[username]\Documents\217417970796890430\VAssessment.exe

IMAGES


Shown above: SmartApeSG script injected into page from a legitimate website.


Shown above: Fake CAPTCHA/verification page generatted by the SmartApeSG traffic, showing the injected ClickFix text to paste into a Run window.


Shown above: Traffic from the infection filtered in Wireshark.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2026/08/21/index.html
如有侵权请联系:admin#unsafe.sh