2025-06-18 (WEDNESDAY): SMARTAPESG --> CLICKFIX LURE --> NETSUPPORT RAT --> STEALC V2

NOTICE:

ASSOCIATED FILES:

 

NOTES

SMARTAPESG NOTES:

 

CLICKFIX NOTES:

 

NETSUPPORT RAT NOTES:

 

STEALC V2 NOTES:

 

INDICATORS OF COMPROMIMSE

DATE/TIME OF INFECTION:

INFECTION CHAIN OF EVENTS:

LEGITIMATE BUT COMPROMISED WEBSITE:

URL FROM SCRIPT INJECTED INTO PAGE FROM COMPROMISED WEBSITE:

TRAFFIC FOR CLICKFIX FAKE VERIFICATION PAGE:

TRAFFIC FROM PASTED SCRIPT TO RETRIEVE THE NETSUPPORT RAT PACKAGE:

ZIP ARCHIVE WITH NETUPPORT RAT PACKAGE:

NETSUPPORT RAT C2 TRAFFIC (UNENCRYPTED HTTP OVER TCP PORT 443):

STEALC V2 PACKAGE SENT OVER NETSUPPORT RAT C2 TRAFFIC AND SAVED TO DISK:

SELECT FILES IN ABOVE ZIP ARCHIVE FOR STEALC V2:

ABOVE DLL FOR STEALC V2 WITH THE PADDING REMOVED

STEALC V2 DATA EXFILTRATION TRAFFIC (UNENCRYPTED HTTP OVER TCP PORT 80):

 

IMAGES


Shown above:  Page from compromised website with injected SmartApeSG script that led to a ClickFix page.

 


Shown above:  ClickFix page presenting instructions to paste script into Run window.

 


Shown above:  Traffic from the infection filtered in Wirehark.

 

Click here to return to the main page.