SL-ADV-2026-WP-001 V13.1.2 lineage TLP:CLEAR

ClickFix / EtherHiding / DonutLoader — 2026-08-03 wave

SecureLeaf / Dispensight · OTX @Dispensight · analysis date 2026-08-03 · 5 detonations + 1 gated non-detonation

5
successful detonations
2
delivery branches (root · /std/)
V13.1.2
version — no 14.x drift
2
durable imphash pivots

1 · Executive summary

Five compromised WordPress lures were detonated on 2026-08-03. All confirmed samples belong to the V13.1.2 lineage — the durable loader (edc8ef44…) and downloader (8e7b065c…) imphashes and the MZER+GetPC prologue at offset 0 all match prior waves, so this is a continuation, not a 14.x variant. The campaign continues to run two operationally-segregated branches — root and /std/ — kept distinct from the C2 domain down to the BSC-testnet EtherHiding contract. Per-victim loader recompile (~60 s pre-detonation) keeps per-sample SHA-256 non-durable; imphash remains the reliable pivot.

2 · Detonation outcomes

Lure host (victim)RegionBranchStage carriedResult
classroom.mindloops.orgCloudflare-fronted/std/WinHTTP downloaderfired
andstudio.ltLithuaniarootCLR-hosting loaderfired
wissmann.co.ilIsrael (recurring)rootCLR-hosting loaderfired
ibrahimstores.comNA-geoip gatedrootCLR-hosting loaderfired (2nd run)
jerseys.co.keKenyaindeterminatenot carvedfired
ibrahimstores.comdefault sandboxgated non-detonation
ibrahimstores.com declined to run in the default sandbox (lure page only, no call-home) and fired only under a North-America geoip gate — the successful run used en-US locale, so geoip, not the German locale, was the gating factor here.

3 · Kill chain

4 · Two-branch delivery model

Markerroot branch/std/ branch
C2 domaindigitalenterprise2026.comsenterprise2026.com
TDS path (dntds.shop)/jsrepo/teamrepo
Staging path/my_enterprise//std_enterprise/
Stage-2 filenamemy_sss.binstudent_s.bin
EtherHiding contract0x7Fd85c09…E4370xFB448D46…D469d

5 · Attacker infrastructure (IOCs)

IndicatorValueRole
IPv4158.94.211.92C2 + stage-2 staging
IPv4178.16.53.137Payload repo / TDS (dntds.shop, TLS/443)
Domaindigitalenterprise2026.comroot C2
Domainsenterprise2026.com/std/ C2
Domaindntds.shopTDS / payload repo
JA36f7889b9fb1a62a9577e685c1fcfa919shared client (both C2 IPs)
BSC contract (root)0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437EtherHiding
BSC contract (/std/)0xFB448D465841C63F3bC433be61Eb692b813D469dEtherHiding

6 · Binary triage

VictimStageImphash (durable)SizeSHA-256 (non-durable)
mindloopsWinHTTP downloader8e7b065c…f96e2350,688 B6270f38b…bca5
andstudioCLR-hosting loaderedc8ef44…f8e1b275,968 B41d8d77a…9e26e
wissmannCLR-hosting loaderedc8ef44…f8e1b275,968 Bb7e7e6c6…2fba6
ibrahimstoresCLR-hosting loaderedc8ef44…f8e1b275,968 B1ef7b229…c888

Prologue 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 at offset 0 on all loader/downloader stages. Four distinct loader SHA-256 across three root victims + one downloader = per-victim recompile confirmed; the newState canary is memory-resident and absent on-disk (expected).

7 · Compromised lures — DO NOT BLOCKLIST

These are victims, not attacker assets. Do not blocklist or report:

andstudio.lt193.46.84.160root
wissmann.co.il185.56.74.85root
jerseys.co.ke68.65.123.79indeterminate
classroom.mindloops.orgCloudflare 104.21.11.43 / 172.67.165.35/std/
ibrahimstores.com82.198.227.68root

BSC / Binance public testnet nodes are abused-legitimate — do not blocklist.

8 · Detection

Companion YARA set SL-ADV-2026-WP-001-V13.1.2-20260803.yar (family prologue, loader & downloader imphash, C2/TDS string anchors — compiled and functionally verified against carved stages). Network side: alert on JSONP handleCmdCheck_ beacons, UA powershell fetching /enterprise/*.bin, JA3 6f7889b9fb1a62a9577e685c1fcfa919, and the two C2 domains / dntds.shop SNI. A companion Suricata ruleset and STIX 2.1 bundle accompany this advisory.

9 · Attribution

Modeled as an unknown intrusion set using AS202412 infrastructure (operator of record "Omegatech LTD", Seychelles bulletproof hosting — an infrastructure provider, not a confirmed actor identity). No named-group or nation-state attribution is asserted. The jerseys.co.ke branch is left indeterminate: it detonated (EtherHiding + svchost injection observed) but this capture yielded no C2/TDS branch markers, no stage carve, and no recoverable contract.