TLP:CLEAR SL-ADV-2026-WP-001 · WAVE V14.9 Dispensight / SecureLeaf

Omegatech ClickFix → Donut infostealer

Recurrence of the WP-002 cluster on the previously-tracked compromised host verrerie-farinelli.com, re-templated with fresh stage and TDS infrastructure. The durable RSA-1024 C2 handshake key is unchanged; delivery infrastructure has rotated.

Advisory
SL-ADV-2026-WP-001
Wave
V14.9
Reported
2026-08-11
Sample ID
260811-1ec5vayzdt
Score
10 / 10
Family
Donut / .NET stealer

01 Summary

This wave was delivered via ClickFix social engineering from the compromised WordPress host verrerie-farinelli.com, which previously appeared in the V14.x line. The page presents a fake Cloudflare Turnstile "verify" widget that plants a clipboard PowerShell one-liner. That one-liner fetches a script from a rotating verification-themed host, which pulls a password-protected ZIP stager containing build.exe — a .NET Donut loader that injects a CLR-hosted infostealer into Chrome and Edge, harvests browser credentials, cookies and wallet data, and establishes persistence through a signed-binary sideload.

Durable anchor — verified this wave

34 embedded CAPI PUBLICKEYBLOB instances were recovered from the injected .NET infostealer's memory (PID 4688). Every one hashes to the durable modulus dc4cb858…febfac6f (e=65537, 1024-bit). The key was recovered from the malicious process address space, not from a host application — confirming the anchor discriminates correctly and remains stable V11 → V14.9.

Scope note — forensic honesty

The tria.ge report tags MZER for this sample, but the specific dumped region (the injected .NET stealer) contains no MZER polyglot header. The MZER anchor lives in the upstream loader stage (my_sss.bin / student_s.bin), not in this artifact. The durable proof recovered here is the C2 key, not the polyglot. The YARA MZER rule is included for loader-stage hunting and intentionally does not fire on this region.

02 Kill chain

1
ClickFix lure Compromised host verrerie-farinelli.com serves a fake Cloudflare Turnstile widget (server-templated, REPLACE_SERVER placeholder) that copies a PowerShell command to the clipboard. T1189 · T1204
2
Clipboard PowerShell (stage-1) Hidden-window, exec-policy-bypassed PowerShell IRM-fetches a script from recaptcha-check.com/8E9curHNH8UfAMLz, writes it to a GUID-named .ps1 in TEMP, and runs it. T1059.001
3
Encrypted ZIP stager Password-protected 7-Zip archive (password RgYcV) extracted to a <hash>.zip_x TEMP directory, yielding build.exe. T1140 · T1027
4
Loader + browser injection build.exe enumerates and injects into Chrome / Edge via NtCreateProcessExOtherParentProcess and WriteProcessMemory, hosting a CLR .NET Donut infostealer. T1055 · T1217
5
Credential theft + C2 Browser credentials, cookies, FTP/WinSCP keys and wallet data collected; AES over raw TCP exfil, session key RSA-wrapped with the durable C2 public key. EtherHiding dual-chain bootstrap (Polygon mainnet + BSC testnet) reads next-stage config via eth_call. T1555 · T1552.001
6
Persistence Signed sideload host LockScreenContentServer.exe + malicious DUI70.dll dropped under C:\ProgramData\c295b490e63c1a9d\, registered via a Run key and a 60-minute scheduled task. T1547.001 · T1053.005 · T1574.002

03 Network IOCs — active infrastructure

All domains below were confirmed live-resolving in behavioral capture 260811-1ec5vayzdt on 2026-08-11 (SNI + resolved IP observed on the wire). Domains rotate per wave — treat as time-bounded IOCs and re-validate before production alerting.

DomainResolved IPRoleClass
verrerie-farinelli.com164.132.235.17ClickFix lure host (compromised WP)Live
recaptcha-check.com172.67.189.119Stage-1 PowerShell fetchLive
cloudflare-check.net94.26.90.126Fake-verify / ClickFix widgetLive
verif-key-code.info178.16.52.101Verify-themed stageLive
dntds.shop178.16.53.137Traffic distribution system (TDS)Live
admetricslab.org91.236.230.87Stage / redirectorLive
ssl.guardhub.info104.21.89.168Stage / redirectorLive
soft-update.dev46.246.97.64Update-themed stageLive
senterprise2026.com158.94.211.92Enterprise-branch stage hostLive
pak.bercak4d.org104.21.70.224Stage / redirectorLive
viewpublicdocuments.com194.213.18.38Document-lure stageLive
openlockeddocuments.com213.232.236.135Document-lure stageLive
pub-5e755c6502f84575a410182fac23ee26.r2.dev104.18.50.34Cloudflare R2 payload bucketLive
Abused legitimate infrastructure — do NOT blocklist

The EtherHiding dual-chain bootstrap reads config through public blockchain RPC nodes. These are legitimate endpoints abused as a read layer. Blocklisting them harms unrelated dApp users and adds noise. Record as observed, not for blocking (splitcam discipline):

  • rpc-mainnet.matic.quiknode.pro Abused-legit
  • polygon.drpc.org Abused-legit
  • bsc-testnet-rpc.publicnode.com Abused-legit

letsdiskuss.com was also observed but appears to be a legitimate (possibly abused) site — validate before listing.

04 Host IOCs — dropped files

build.exe New
.NET Donut loader / infostealer. Per-lure recompiled — SHA-256 churns per wave; anchor on the durable C2 key, not this hash.
Extracted from stager ZIP → <hash>.zip_x\build.exe
stager.zip
SHA-256 c18abede767638f3bd5ac6d828dee17685396c51961aff2cba3d9ca94a8f8b6d
7-Zip archive, password RgYcV. Contains build.exe.
LockScreenContentServer.exe
SHA-256 de9d325af3156232c34916840210efb5706d6e6a5eba1827c8240e4f71c09fa2
Signed sideload host (persistence). Legit binary abused.
DUI70.dll
SHA-256 f91290524136a668207c20e7d7d8f122976673ba4323a4fb7d8cf4b7e983e151
Malicious sideloaded DLL, loaded by the host binary.
1.bat
SHA-256 a132e64885c60235cd18ade666463c565da70ebd9eeebce4dd40d53680aad33d
Launcher for the persistence host.

Host artifacts

05 Durable C2 key

The RSA-1024 CAPI handshake public key remains the cluster's most stable pivot. The client RSA-wraps its AES session key with this public key before exfil. Reused unchanged across every tracked wave.

# CAPI PUBLICKEYBLOB
bType        06        (PUBLICKEYBLOB)
bVersion     02
aiKeyAlg     00 A4 00 00  (CALG_RSA_KEYX)
magic        "RSA1"
bitlen       1024
pubexp       65537

# SHA-256 of big-endian modulus (the durable anchor)
dc4cb85885ffcf7bfa6f37c8ac4a8334a9504c06df0307a599c67ee2febfac6f

Recovery this wave: 34 blob instances in PID 4688 (injected .NET infostealer), all matching. Verified by carving the blob, reversing the little-endian modulus to big-endian, and hashing — no eyeballing of digits.

06 MITRE ATT&CK

TacticTechniqueID
Initial AccessDrive-by / compromised siteT1189
ExecutionPowerShell (ClickFix)T1059.001
ExecutionWindows Command ShellT1059.003
Persistence / PrivEscRegistry Run KeysT1547.001
Persistence / PrivEscScheduled TaskT1053.005
Defense EvasionDLL side-loadingT1574.002
Defense EvasionProcess injectionT1055
Credential AccessCredentials from browsersT1555.003
Credential AccessCredentials in filesT1552.001
DiscoveryBrowser information discoveryT1217
CollectionData from local systemT1005

07 Wave delta vs. prior V14.x

ComponentStatus this wave
RSA-1024 C2 key (dc4cb858…)Unchanged durable anchor holds
Lure host verrerie-farinelli.comRecurring — re-templated with fresh stage set
Stage / TDS / verify domainsRotated — new active set (see §03)
Loader build.exeNew per-lure SHA-256 (hash churns; behavior stable)
Persistence hostLockScreenContentServer.exe sideload — consistent with prior
EtherHiding bootstrapDual-chain (Polygon mainnet + BSC testnet) — consistent

Read: same durable key, new delivery infrastructure — the expected rotation profile (cheap layer churns, expensive layer frozen).

08 Detection & response

09 Companion machine-readable artifacts