2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN PUSHES UNIDENTIFIED RAT

NOTICE:

ASSOCIATED FILES:

 

2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX PUSHES UNIDENTIFIED RAT

SMARTAPESG TRAFFIC LEADING TO FAKE CAPTCH/HUMAN VERIFICATION PAGE:

- https[:]//pewtercanto[.]top/user/throttle-effect.js
- https[:]//pewtercanto[.]top/user/throttle-effect.js
- https[:]//pewtercanto[.]top/user/acl-dom?JSMlAATp
- https[:]//pewtercanto[.]top/user/version-deploy.js?18c7713e5fb5a572

TRAFFIC GENERATED FROM RUNNING THE CLIPBOARD-INJECTED TEXT IN A RUN WINDOW:

- hxxp[:]//deltaode[.]com/po  <-- 302 redirect to HTTPS URL
- hxxps[:]//deltaode[.]com/po
- hxxp[:]//deltaode[.]com/wv  <-- 302 redirect to HTTPS URL
- hxxps[:]//deltaode[.]com/wv

INITIAL HTA FILE:

- SHA256 hash: e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832
- File size: 39,487 bytes
- File type: HTML document text, ASCII text, with very long lines (4879)
- File location: hxxps[:]//deltaode[.]compo
- File location: C:\Users\[username]\AppData\Local\ACER.xam
- File description: HTA file used to download malicious zip archive then extract and run the content

DOWNLOADED ZIP ARCHIVE:

- SHA256 hash: 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275
- File size: 13,991,507 bytes
- File type: Zip archive data, at least v2.0 to extract, compression method=deflate
- File location: hxxps[:]//deltaode[.]com/wv
- File location: C:\Users\[username]\Documents\553003097200721800\553003097200721800.pdf
- File description: File for legitimate program that uses DLL side-loading for an undentified RAT

POST-INFECTION TRAFFIC FROM UNIDENTIFIED RAT:

- TCP port 443 - dns[.]google - secure DNS query (not malicious)
- 89.124.79[.]98 port 443 - encoded or otherwise encrypted TCP traffic to C2 server for unidentified RAT

 

IMAGES


Shown above: SmartApeSG script injected into page from legitimate but compromised website.

 


Shown above: Fake CAPTCHA (human verification) page showing ClickFix instructions pasted into a run Window.

 


Shown above: Traffic from the infection filtered in Wireshark.

 

Click here to return to the main page.