SecureLeaf / Dispensight · OTX @Dispensight · analysis date 2026-08-03 · 5 detonations + 1 gated non-detonation
Five compromised WordPress lures were detonated on 2026-08-03. All confirmed samples belong to the
V13.1.2 lineage — the durable loader (edc8ef44…) and downloader
(8e7b065c…) imphashes and the MZER+GetPC prologue at offset 0 all match prior waves,
so this is a continuation, not a 14.x variant. The campaign continues to run two
operationally-segregated branches — root and /std/ —
kept distinct from the C2 domain down to the BSC-testnet EtherHiding contract. Per-victim loader recompile
(~60 s pre-detonation) keeps per-sample SHA-256 non-durable; imphash remains the reliable pivot.
| Lure host (victim) | Region | Branch | Stage carried | Result |
|---|---|---|---|---|
| classroom.mindloops.org | Cloudflare-fronted | /std/ | WinHTTP downloader | fired |
| andstudio.lt | Lithuania | root | CLR-hosting loader | fired |
| wissmann.co.il | Israel (recurring) | root | CLR-hosting loader | fired |
| ibrahimstores.com | NA-geoip gated | root | CLR-hosting loader | fired (2nd run) |
| jerseys.co.ke | Kenya | indeterminate | not carved | fired |
| ibrahimstores.com | default sandbox | — | — | gated non-detonation |
en-US locale,
so geoip, not the German locale, was the gating factor here.eth_call (selector 0x6d4ce63c) — EtherHiding, per-branch contract.?callback=handleCmdCheck_<epoch_ms>_<seq> to the per-branch C2 (~1 s cadence) and pulls stage-2 /enterprise/my_sss.bin with UA powershell.MZER polyglot loader → Donut shellcode → injection into svchost.exe; post-injection beacon to login.live.com (/RST2.srf, /ppsecure/DeviceUpdate.srf).| Marker | root branch | /std/ branch |
|---|---|---|
| C2 domain | digitalenterprise2026.com | senterprise2026.com |
| TDS path (dntds.shop) | /jsrepo | /teamrepo |
| Staging path | /my_enterprise/ | /std_enterprise/ |
| Stage-2 filename | my_sss.bin | student_s.bin |
| EtherHiding contract | 0x7Fd85c09…E437 | 0xFB448D46…D469d |
| Indicator | Value | Role |
|---|---|---|
| IPv4 | 158.94.211.92 | C2 + stage-2 staging |
| IPv4 | 178.16.53.137 | Payload repo / TDS (dntds.shop, TLS/443) |
| Domain | digitalenterprise2026.com | root C2 |
| Domain | senterprise2026.com | /std/ C2 |
| Domain | dntds.shop | TDS / payload repo |
| JA3 | 6f7889b9fb1a62a9577e685c1fcfa919 | shared client (both C2 IPs) |
| BSC contract (root) | 0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437 | EtherHiding |
| BSC contract (/std/) | 0xFB448D465841C63F3bC433be61Eb692b813D469d | EtherHiding |
| Victim | Stage | Imphash (durable) | Size | SHA-256 (non-durable) |
|---|---|---|---|---|
| mindloops | WinHTTP downloader | 8e7b065c…f96e23 | 50,688 B | 6270f38b…bca5 |
| andstudio | CLR-hosting loader | edc8ef44…f8e1b | 275,968 B | 41d8d77a…9e26e |
| wissmann | CLR-hosting loader | edc8ef44…f8e1b | 275,968 B | b7e7e6c6…2fba6 |
| ibrahimstores | CLR-hosting loader | edc8ef44…f8e1b | 275,968 B | 1ef7b229…c888 |
Prologue 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 at offset 0 on all loader/downloader stages.
Four distinct loader SHA-256 across three root victims + one downloader = per-victim recompile confirmed;
the newState canary is memory-resident and absent on-disk (expected).
These are victims, not attacker assets. Do not blocklist or report:
| andstudio.lt | 193.46.84.160 | root |
| wissmann.co.il | 185.56.74.85 | root |
| jerseys.co.ke | 68.65.123.79 | indeterminate |
| classroom.mindloops.org | Cloudflare 104.21.11.43 / 172.67.165.35 | /std/ |
| ibrahimstores.com | 82.198.227.68 | root |
BSC / Binance public testnet nodes are abused-legitimate — do not blocklist.
Companion YARA set SL-ADV-2026-WP-001-V13.1.2-20260803.yar (family prologue, loader & downloader
imphash, C2/TDS string anchors — compiled and functionally verified against carved stages). Network side:
alert on JSONP handleCmdCheck_ beacons, UA powershell fetching /enterprise/*.bin,
JA3 6f7889b9fb1a62a9577e685c1fcfa919, and the two C2 domains / dntds.shop SNI. A companion Suricata
ruleset and STIX 2.1 bundle accompany this advisory.
Modeled as an unknown intrusion set using AS202412 infrastructure (operator of record
"Omegatech LTD", Seychelles bulletproof hosting — an infrastructure provider, not a confirmed actor identity).
No named-group or nation-state attribution is asserted. The jerseys.co.ke branch is
left indeterminate: it detonated (EtherHiding + svchost injection observed) but this capture yielded no
C2/TDS branch markers, no stage carve, and no recoverable contract.