SecureLeaf Threat Advisory · Dispensight CTI

Omegatech ClickFix → EtherHiding → DonutLoader — Version 11.2 — PCAP-validated (lure: splitcam.com)

BSC-testnet EtherHiding · in-memory C# compile · Donut shellcode → svchost.exe
Severity: Critical Advisory: SL-ADV-2026-WP-001 (V11.2) Family: DonutLoader tria.ge score: 10/10 Published: 2026-06-27 Revised: 2026-06-29 (full PCAP) TLP: CLEAR

1. Executive summary

SecureLeaf has tracked the Omegatech ClickFix/EtherHiding cluster from V1 through V11. V11 uses the compromised legitimate site splitcam.com as its lure and delivers the same DonutLoader end-stage seen in V7–V10. Two material changes this version: the blockchain-hosted stage moved from BSC mainnet to BSC testnet, and the second-stage path was renamed to /my_enterprise/. Backend delivery infrastructure remains constant on 158.94.208.0/24, which keeps V11 firmly attached to the prior cluster.

Confirmation is drawn from two tria.ge detonations (win11 + win10) and a behavioral PCAP. The win10 run additionally exposes the persistence arm (Task Scheduler COM) that the win11 run did not reach.

V11.1 revision. A full 53 MB behavioral PCAP (any.run da400bb8) was obtained and analysed. It confirms the delivery chain and backend constancy, but corrects three V11 claims: (a) the sesame-open-yourself stage-2 UA does not appear (0 hits) — real fetch UAs are powershell and WindowsPowerShell/5.1.19041.4046; (b) EtherHiding ran over TLS to publicnode, not cleartext :8545 (the prebsc seed was never contacted); (c) my_s.bin as served is MZER-polyglot Donut shellcode (opens 4D 5A 45 52 + GetPC stub), not a true PE. It also upgrades 178.16.53.137 from “TDS” to primary encrypted payload host (31.58 MB over TLS). See §8.

2. TTP evolution vs V7–V10

DimensionV7–V10V11 (this advisory)
Lure vectorcompromised WordPress hostscompromised splitcam.com (CF-fronted)
EtherHiding chainBSC mainnetBSC testnet (publicnode + prebsc seed:8545)
Stage-2 path(prior paths)/my_enterprise/
Delivery infra158.94.208.0/24158.94.208.0/24 (unchanged)
End-stageDonutLoader → svchostDonutLoader → svchost (unchanged)

3. Kill chain

  1. Victim browser loads splitcam.com (compromised; Cloudflare-fronted 172.67.148.86 / 104.21.39.190), which serves an obfuscator.io + RC4 loader.
  2. Loader issues a BSC testnet eth_call over TLS/443 to bsc-testnet-rpc.publicnode.com (104.20.24.117 / 172.66.150.162) to read the hidden contract (EtherHiding). PCAP: no cleartext :8545 and no contact to the prebsc seed — contract address is not recoverable from this encrypted channel (recovered post-hoc from loader memory — see §11).
  3. ClickFix UI tricks the user into pasting a PowerShell one-liner that fetches the cradle: GET http://158.94.208.92/?sid=<epoch-ms>-<rand>.
  4. Cradle sets stage-2 base http://158.94.208.104/my_enterprise → 301 → /my_enterprise/ (cleartext nginx).
  5. Stage-2 pulls /enterprise/my_s.binserved as MZER-polyglot Donut shellcode (284,160 B): opens 4D 5A 45 52 (“MZER”, self-cancelling reg ops) then E8 00 00 00 00 / 59 / 48 83 E9 09 = call $+5 → pop rcx → sub rcx,9 (GetPC stub). It is position-independent shellcode wearing an MZ hat, not a true PE. /my_enterprise/ itself returns a 53,323 B opaque blob (0xE8 CALL prologue, shellcode-like). PCAP note: /enterprise/my_downloader.bin and the …_zip_… blob were not fetched in this run.
  6. PowerShell compiles C# in memory: csc.execvtres.exemc5z3xll.dll.
  7. Donut shellcode is reflectively loaded and injected via WriteProcessMemory into svchost.exe (win11). On win10, Task Scheduler COM establishes persistence.
Telemetry note. The sid token is <epoch-ms click time>-<rand> — observed values 1782587888594-4xwumw3z and (PCAP) 1782706624767-sfjppp33 decode to the detonation click time, confirming per-victim tracking fires end-to-end.

4. Indicators of Compromise

REPORTABLE high-confidence malicious · DO-NOT-BLOCKLIST compromised/abused-legitimate · FINGERPRINT cluster signal

4.1 Network infrastructure

IndicatorValueRoleClass
Cradle / beacon IP158.94.208.92 (80,443)ClickFix stage-2 retrieval; = digitalenterprise2026.comREPORTABLE
Stage-2 host158.94.208.104 (80)cleartext nginx payload host (/my_enterprise/)REPORTABLE
TDS178.16.53.137 (NL)dntds.shop — primary payload host; 31.58 MB over TLS/443 (PCAP)REPORTABLE
TDS-adjacent178.16.53.43 (80)same /24, cleartext contactREPORTABLE
Aux C291.92.243.161:3038odd-port callback — CONFIRMED active (13 pkts, cleartext custom proto, PCAP)REPORTABLE
Domaindntds.shopTDSREPORTABLE
Domaindigitalenterprise2026.combeacon/cradle (158.94.208.92)REPORTABLE
Lure hostsplitcam.comcompromised victim (CF-fronted)DO-NOT-BLOCKLIST
BSC testnet RPCbsc-testnet-rpc.publicnode.com (104.20.24.117 / 172.66.150.162)abused legitimate (EtherHiding, TLS/443 — channel actually used)DO-NOT-BLOCKLIST
BSC testnet seeddata-seed-prebsc-1-s1.binance.org:8545abused legitimate — NOT contacted in PCAP (no :8545 traffic)DO-NOT-BLOCKLIST
Benign noise (excluded)92.223.97.79msedge.b.tlu.dl.delivery.mp.microsoft.com (MS BITS / Akamai) — do NOT reportDO-NOT-BLOCKLIST

4.2 URLs / paths

URLStage
http://158.94.208.92/?sid=<epochms>-<rand>ClickFix cradle
http://158.94.208.104/my_enterprise/stage-2 landing (301 from /my_enterprise)
http://158.94.208.104/enterprise/my_s.binDonut shellcode
http://158.94.208.104/enterprise/my_downloader.bindownloader

4.3 Host artifacts (hashes)

FileSHA-256
mc5z3xll.dll85aceb0cf14b0c6dc327df2939d2922e71b3169dca5078708249d534c0a409e1
mc5z3xll.0.csf08c2ad3bf501e5dc9aa4f271d1f81aa286af3cdc63358fbddf1592c43cb74a1
mc5z3xll.cmdlinec7b3b1f009b26e0c03101f3ac7a52d27b83c48ad3ca3ea4de33da68cb8c81729
my_s.bin (served, MZER-polyglot Donut shellcode, 284160B)c835f1a1da7a3c22e92e1d0a8d6781fbd77f9016fb431e2c71d8dbe7c6295253
/my_enterprise/ body (53323B, shellcode-like)1957217fe2e5b5fd4ff13dd166aed003f70756c7d8ac0edd966086db789c2533
ClickFix cradle page (158.94.208.92, 1697B)a3147e729a5e9c10071197463588c4d55381ccc1c1b10d6ad92af6c64594185c
[mem] Donut region PID792 (MZER@0x0, 286720B) — volatile/corroboration1db7a1acc730afe86772cc56cab90d161c6ce8a33efb14b0c592bba741077f49
[mem] loader working-mem PID936 (holds contract+UA+seed) — volatile/corroboration80860399af45d0ce5861cf18d7d56da6cce42c42608047e39e1e844c8b638a2e

4.4 Behavioral fingerprint

FINGERPRINT Correction (V11.2): the sesame-open-yourself UA was not observed in the full PCAP (0 hits) and is unconfirmed for V11. The stage-2 retrieval UAs actually seen are bare powershell (for my_s.bin) and Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.4046 (cradle + /my_enterprise[/]). Pivot on those.

FINGERPRINT Reconciliation (V11.2): memory forensics show sesame-open-yourself is compiled into the loader (10 hits, PID 936 string table). It is a genuine kit string that was simply not emitted on the wire in the da400bb8 run. Status: unconfirmed → confirmed-in-loader (run-dependent emission). See §11.

FINGERPRINT MZER prologue. Served stage payloads open with 4D 5A 45 52 (“MZER”) immediately followed by a GetPC stub (E8 00 00 00 00 59 48 83 E9 09). This polyglot header is observed across the V-series and is a far stronger cluster signal than a bare MZ match. Anchor detection at file offset 0.

Prefix correlation. 158.94.208.92 and 158.94.208.104 both sit in 158.94.208.0/24. Run against the AS202412 (Omegatech LTD) prefix-match rule — a hit is another structural-twin confirmation and elevates attribution confidence.
Reconciliation. The empty-string SHA-256 e3b0c44…b855 appears legitimately as the zero-length crashpad pipe and must not be conflated with the decoy challengeHash in the loader's ClickFix insert.

5. MITRE ATT&CK

TacticTechniqueObserved
Initial AccessT1189Drive-by via compromised splitcam.com
Command & ControlT1659Content injection / EtherHiding (BSC testnet)
ExecutionT1204.004ClickFix copy-paste user execution
ExecutionT1059.001PowerShell cradle
Defense EvasionT1027.004Compile-after-delivery (csc.exe/cvtres.exe)
Defense EvasionT1140obfuscator.io + RC4 loader decode
Defense Evasion / ExecutionT1620Reflective code loading (Donut)
Privilege Esc. / Def. EvasionT1055WriteProcessMemory → svchost.exe
PersistenceT1053.005Task Scheduler COM (win10)
DiscoveryT1217 / T1012 / T1082 / T1124browser / registry / system info / time

6. Detection & response

Hunt

· powershell.exe spawning csc.exe/cvtres.exe then writing to svchost.exe.
· Outbound TLS to bsc-testnet-rpc.publicnode.com from a browser child process (testnet EtherHiding; :8545 not used this campaign run).
· HTTP requests with UA sesame-open-yourself.
· Any contact to 158.94.208.0/24 or /my_enterprise/.

Respond

· Block reportable IPs/domains (§4.1); spare CF/Binance/legit infra.
· Remove Task Scheduler COM persistence (win10 arm).
· Submit reportable hosts to AbuseIPDB/OTX under handle Dispensight.
· Notify splitcam.com operators (compromised victim).

YARA — MZER prologue (cross-version)

rule Omegatech_MZER_Donut_Prologue
{
    meta:
        author      = "Dispensight (SecureLeaf)"
        advisory    = "SL-ADV-2026-WP-001 (V11.2)"
        description = "MZER polyglot header + GetPC stub on served stage payloads"
        reference   = "any.run da400bb8; my_s.bin c835f1a1...295253"
        tlp         = "CLEAR"
    strings:
        // 'MZER' (self-cancelling reg ops) -> call $+5 -> pop rcx -> sub rcx,9
        $mzer_getpc = { 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 }
    condition:
        $mzer_getpc at 0
}

Header-anchored; low FP. Tighten/loosen by trimming the trailing 48 83 E9 09 if blob alignment shifts across versions.

8. PCAP validation & corrections (any.run da400bb8)

Source: 53 MB behavioral capture, victim 192.168.100.4 / DESKTOP-JGLLJLD (win10 19045), 183 s, 60,174 packets. any.run task da400bb8.

Claim in V11PCAP findingDisposition
Stage-2 UA sesame-open-yourself0 occurrences; real UAs = powershell / WindowsPowerShell/5.1.19041.4046CORRECTED
EtherHiding via cleartext :8545 + prebsc seed0 packets to :8545; seed never resolved/contacted; RPC = publicnode over TLS/443CORRECTED
my_s.bin = shellcodeserved blob opens 4D 5A 45 52 (‘MZER’) + GetPC stub = polyglot Donut shellcode, NOT a PE; the 53323B /my_enterprise/ body is a second shellcode blob (0xE8)CORRECTED
178.16.53.137 = TDS31.58 MB delivered over TLS/443 — primary encrypted payload hostUPGRADED
91.92.243.161:3038 aux C2CONFIRMED active: 13 pkts, cleartext custom binary proto (not TLS)CONFIRMED
Per-victim sid trackingnew instance 1782706624767-sfjppp33 → click time 2026-06-29 04:17ZCONFIRMED
my_downloader.bin / _zip_ blob / 178.16.53.43not exercised in this run (absence ≠ benign)UNOBSERVED
92.223.97.79 (candidate)= msedge MS-BITS/Akamai delivery — benignEXCLUDED

DNS confirmations: dntds.shop → 178.16.53.137; digitalenterprise2026.com → 158.94.208.92 (SNI-confirmed); splitcam.com → 104.21.39.190 / 172.67.148.86 (CF). EtherHiding contract address is not recoverable — the publicnode RPC channel is TLS-encrypted.

9. References

· tria.ge behavioral (win11): 260627-xsnlysdt3q
· tria.ge behavioral (win10): 260627-xzmcgacz4x
· STIX 2.1 bundle: SL-ADV-2026-WP-001_V11.stix.json (TAXII: taxii.dispensight.ca)
· any.run behavioral PCAP: da400bb8-b2d8-4c93-9e10-17ffb7a7166f
· STIX 2.1 bundle (enriched): SL-ADV-2026-WP-001_V11.1_stix.json
· AbuseIPDB bulk report: SL-ADV-2026-WP-001_V11.1_abuseipdb.csv (4 PCAP-observed hosts)
· Prior cluster: SL-ADV-2026-WP-001 V1–V10

10. Changelog

VersionDateChange
V11.22026-06-29 Memory-forensics enrichment (splitcam-memdump). Recovered the EtherHiding contract 0xa44DFB63dd4937983195c80d83387a10567496FC from loader memory (closes V11.1 §8 gap). Reconciled sesame-open-yourself UA (unconfirmed → confirmed-in-loader, run-dependent emission). prebsc seed config-resident but not contacted. Backend constancy + MZER@0x0 re-confirmed from memory. Added memory-region corroboration hashes (volatile). See §11.
V11.12026-06-29 Full-PCAP validation (any.run da400bb8). Corrections: (a) sesame-open-yourself UA not observed — real fetch UAs are powershell / WindowsPowerShell/5.1.19041.4046; (b) EtherHiding ran over TLS to bsc-testnet-rpc.publicnode.com, not cleartext :8545 (prebsc seed never contacted); (c) my_s.bin re-characterized from “PE/MZ” to MZER-polyglot Donut shellcode (GetPC stub). Upgrades: 178.16.53.137 → primary encrypted payload host (31.58 MB TLS). Additions: served-payload SHA-256s, Omegatech_MZER_Donut_Prologue YARA rule, aux-C2 91.92.243.161:3038 confirmation, new cradle sid instance. Excluded 92.223.97.79 (MS BITS/Akamai, benign). 178.16.53.43 / my_downloader.bin / _zip_ blob not exercised this run.
V112026-06-27 Initial V11. New lure splitcam.com (CF-fronted); EtherHiding moved BSC mainnet → testnet; stage-2 path renamed /my_enterprise/; backend constant on 158.94.208.0/24; DonutLoader end-stage unchanged. Two tria.ge detonations (win11 + win10).
V1–V10prior Omegatech ClickFix/EtherHiding cluster tracking: JS loader deobfuscation, STIX/TAXII maintenance, AS202412 (Omegatech LTD) attribution, ColocaTel AS213438 structural twin, mid-investigation retraction SL-RETRACT-2026-001. See prior advisories.

11. Memory-forensics enrichment (V11.2)

Source: splitcam-memdump (Recorded Future sandbox, 34 region dumps across PID 792/936/1116/5272, 2026-06-29). Static analysis only — no payload bytes reproduced; indicators key on memory-resident strings/hashes.

EtherHiding contract recovered. The BSC-testnet contract the V11.1 PCAP could not yield (publicnode RPC over TLS/443) is cleartext-resident in loader memory (PID 936, region 0x1C521600000):
0xa44DFB63dd4937983195c80d83387a10567496FC REPORTABLE
This enables pulling the hidden contract payload directly off BSC testnet.
FindingDisposition
sesame-open-yourself UACompiled into loader (10 hits, PID 936); NOT wire-emitted in da400bb8. unconfirmed → confirmed-in-loader (run-dependent).
prebsc seed data-seed-prebsc-1-s1.binance.org:8545Config-resident in memory but not contacted — consistent with PCAP. Presence in config ≠ contacted.
EtherHiding contract 0xa44DFB63dd4937983195c80d83387a10567496FCRECOVERED from loader memory — closes the V11.1 §8 “not recoverable” gap.
Backend constancy (158.94.208.104, my_s.bin, my_downloader)Re-confirmed from memory, independent of PCAP.
MZER polyglot prologuePresent at offset 0 in PID 792 (286720B region) & PID 936 — second evidence source for the Donut payload.

Caveat: memory-region SHA-256s are volatile (per-snapshot) — provided as corroboration/provenance, not durable blocklist IOCs. The contract address and UA string are the durable additions.