SecureLeaf Advisory · SL-ADV-2026-WP-001 · V13.1.2
A ClickFix → BSC-testnet EtherHiding → DonutLoader kill chain, now running two operationally-segregated delivery branches that are separated all the way down to the blockchain layer. Documented from four live detonations on 2026-08-01.
Unknown intrusion set using AS202412 infrastructure. This advisory asserts only what the telemetry proves: every hostile hop is BGP-homed in AS202412 (Omegatech LTD, Seychelles bulletproof hosting). Confidence in the infrastructure linkage is high. No named-group, nation-state, or actor-identity attribution is made or implied — and none is warranted by the evidence in hand.
01
The cluster tracked since V8 as “Omegatech ClickFix” continues under the same kill chain: a compromised website reads a base64 JavaScript payload out of a BNB-Smart-Chain testnet smart contract (EtherHiding), presents a fake-verification ClickFix lure that pastes a PowerShell cradle, compiles a C# stub in memory (csc.exe/cvtres.exe), and runs a two-stage MZER-polyglot Donut loader that injects into svchost.exe and persists via a Task Scheduler COM object.
What is materially new in V13.1.2 is structural, not mechanical: the operator now runs two parallel delivery branches — a root template and a /std/ template — that share one C2 IP and one payload host but keep separate beacon domains, separate payload-host domains, and separate EtherHiding contracts. The branches are segregated down to the blockchain layer. Four lures detonated within a ~9-minute window on 2026-08-01 resolve cleanly into this one wave.
02
Identical across both branches; only the paths, domains, and contract differ.
03
The operator recompiles the loader within about a minute of each victim hitting the cradle, which kills per-sample SHA-256 as a pivot. Track the invariants instead.
04
Both branches ride the same C2 IP (158.94.211.92, AS202412) and the same payload host (178.16.53.137, NL), but are otherwise parallel — including a distinct EtherHiding contract each.
| Attribute | root | /std/ |
|---|---|---|
| Cradle path | /?sid=<ms>-<rnd> | /std/?sid=<ms>-<rnd> |
| Stage directory | /my_enterprise/ | /std_enterprise/ · /enterprise/ |
| Loader artifact | my_sss.bin | student_s.bin |
| JSONP beacon domain | digitalenterprise2026.com | senterprise2026.com |
| Payload host domain | dntds.shop | sdntds.shop |
| BSC EtherHiding contract | 0x7Fd85c09…E437 | 0xFB448D46…469d |
| Lures (2026-08-01) | munis-minibus.com | worrigeesports.com.au · martvarauto.ee · besen-group.com |
158.94.211.92 · aux 158.94.208.92:61120 · payload 178.16.53.137 · downloader 8e7b065c · loader edc8ef44 · MZER/GetPC prologue · bsc-testnet.bnbchain.org primary with bsc-testnet-rpc.publicnode.com failover.05
A calibrated diff against prior versions of the same cluster. Only genuine deltas are listed.
| Dimension | V8 – V13.1.1 (prior) | V13.1.2 (this wave) |
|---|---|---|
| Delivery templates | Single track | Two concurrent branches (root + /std/) |
| EtherHiding contracts | Single contract | One contract per branch — segregated at the chain layer |
| Loader recompile cadence | Per-wave (V13.1.1) | Per-victim, ≈60s before detonation |
| Beacon / payload domains | process.iconnode.com; earlier hosts | *enterprise2026.com beacons; dntds.shop / sdntds.shop payload repos (/jsrepo) |
| Stage-2 transport | V11: cleartext HTTP cradle | Cleartext IP cradle and TLS domain beacon in parallel; MZER served over cleartext :80 |
| Injector vector | Shadow-DOM (V2); obfuscator.io inline (V13.1.1) | Inline-HTML and jquery-migrate library-append both observed |
| Lure geography | UK / IL / FR / ME focus | Widened: AU · EE · RS · US |
| Native chain shape | Under-characterised second stage | Confirmed two-stage: WinHTTP downloader (8e7b065c) → CLR-host loader (edc8ef44) |
Consistent with prior versions (not new): the MZER polyglot header with GetPC bootstrap, the Donut/CLR-hosting architecture, the ClickFix→PowerShell→csc.exe in-memory compile, svchost injection, Task Scheduler COM persistence, BSC-testnet (not mainnet) EtherHiding, and the ipinfo.io geolocation check.
06
Four samples, one wave. sid values are per-victim epoch-ms tokens; each decodes to its own detonation minute, confirming live per-victim tracking. All lure hosts are compromised victims.
| Lure (victim) | Geo / host | Branch | sid → UTC | Loader compiled |
|---|---|---|---|---|
| worrigeesports.com.au | AU · 23.235.217.105 | /std/ | 02:0x | 08-01 01:42:41 |
| munis-minibus.com | RS · 185.119.89.171 | root | 02:02:50 | 08-01 01:42:41 |
| martvarauto.ee | EE · 185.7.252.210 | /std/ | 02:07:35 | 08-01 02:07:41 |
| besen-group.com | US/GCP · 35.212.53.5 | /std/ | 02:11:19 | 08-01 02:10:41 |
07
| Type | Value | Context |
|---|---|---|
| BSC contract | 0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437 | root · get() 0x6d4ce63c |
| BSC contract | 0xFB448D465841C63F3bC433be61Eb692b813D469d | /std/ · get() 0x6d4ce63c |
| imphash (loader) | edc8ef44e1870aad7a3e58dab17f8e1b | CLR-host MZER loader |
| imphash (downloader) | 8e7b065c967657cca657d11206f96e23 | WinHTTP MZER downloader |
| byte prologue | 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 48 8B | MZER + GetPC, both stages |
| Indicator | Role | Report |
|---|---|---|
| 158.94.211.92 | C2 / cradle + both beacon domains | block |
| 158.94.208.92:61120 | Aux stage host (AS202412) | block |
| 178.16.53.137 | Encrypted payload host (NL) — dntds.shop / sdntds.shop /jsrepo | block |
| digitalenterprise2026.com | Root JSONP beacon | block |
| senterprise2026.com | /std/ JSONP beacon | block |
| dntds.shop · sdntds.shop | Payload repos (root · /std/) | block |
| 172.111.246.0/24 | New AS202412 announcement (2026-08-01) | monitor — not yet used |
| Pattern | Detail |
|---|---|
| callback=handleCmdCheck_<ms>_<seq> | JSONP command-poll; response handleCmdCheck_<…>({"executed":false}) |
| ?sid=<13-digit ms>-<rand> | Per-victim tracking token on cradle + beacon |
| /jsrepo?rnd=<float>&ts=<ms> | Stage-2 payload fetch on dntds.shop / sdntds.shop |
| ?ob=open-bridge/events | Injector beacon on the compromised lure |
08
bsc-testnet.bnbchain.org and bsc-testnet-rpc.publicnode.com (public BSC RPC), ipinfo.io, and the Microsoft / Google / Meta / analytics telemetry seen in the captures. The malice is the contract read, not the RPC endpoint.09
| Tactic | Technique |
|---|---|
| Initial Access / Execution | T1204.004 ClickFix · T1059.001 PowerShell · T1059.007 JavaScript |
| Defense Evasion | T1027 Obfuscation · T1140 Deobfuscate · T1055 Process Injection · T1620 Reflective Code Loading |
| Command & Control | T1102 Web Service (EtherHiding + JSONP) · T1105 Ingress Tool Transfer |
| Persistence | T1053.005 Scheduled Task (COM) |
| Discovery | T1614 System Location (ipinfo.io) · T1082 System Info · T1012 Query Registry |
10
Full ruleset ships alongside this advisory as SL-ADV-2026-WP-001-V13.1.2.yar (6 rules) and …stix2.json. Highest-fidelity anchors:
4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 48 8B (catches both stages, both branches).mscoree/CorBindToRuntime/.fptable → loader; WinHttp*/CreateRemoteThread → downloader.handleCmdCheck_[0-9]{10,}_[0-9]{1,4}\(\{"executed":(true|false)\}\) in proxy logs or process memory.eth_call + selector 0x6d4ce63c, or either branch contract literal, in TLS-inspected or memory data.Verified: the loader rule matched the CLR-host stages carved from both martvarauto.ee and besen-group.com; the downloader rule matched the WinHTTP stage from munis-minibus.com and both /std/ lures — with clean separation between the two.