2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN PUSHES UNIDENTIFIED RAT
NOTICE:
- Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.
ASSOCIATED FILES:
- 2026-07-31-IOCs-from-SmartApeSG-activity.txt.zip 1.3 kB (1,304 bytes)
- 2026-07-31-SmartApeSG-HTTPS-traffic.zip 335.8 kB (335,751 bytes)
- 2026-07-31-SmartApeSG-activity.pcap.zip 18.0 MB (18,009,157 bytes)
- 2026-07-31-SmartApeSG-files.zip 13.9 MB (13,946,488 bytes)
2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX PUSHES UNIDENTIFIED RAT SMARTAPESG TRAFFIC LEADING TO FAKE CAPTCH/HUMAN VERIFICATION PAGE: - https[:]//pewtercanto[.]top/user/throttle-effect.js - https[:]//pewtercanto[.]top/user/throttle-effect.js - https[:]//pewtercanto[.]top/user/acl-dom?JSMlAATp - https[:]//pewtercanto[.]top/user/version-deploy.js?18c7713e5fb5a572 TRAFFIC GENERATED FROM RUNNING THE CLIPBOARD-INJECTED TEXT IN A RUN WINDOW: - hxxp[:]//deltaode[.]com/po <-- 302 redirect to HTTPS URL - hxxps[:]//deltaode[.]com/po - hxxp[:]//deltaode[.]com/wv <-- 302 redirect to HTTPS URL - hxxps[:]//deltaode[.]com/wv INITIAL HTA FILE: - SHA256 hash: e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832 - File size: 39,487 bytes - File type: HTML document text, ASCII text, with very long lines (4879) - File location: hxxps[:]//deltaode[.]compo - File location: C:\Users\[username]\AppData\Local\ACER.xam - File description: HTA file used to download malicious zip archive then extract and run the content DOWNLOADED ZIP ARCHIVE: - SHA256 hash: 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275 - File size: 13,991,507 bytes - File type: Zip archive data, at least v2.0 to extract, compression method=deflate - File location: hxxps[:]//deltaode[.]com/wv - File location: C:\Users\[username]\Documents\553003097200721800\553003097200721800.pdf - File description: File for legitimate program that uses DLL side-loading for an undentified RAT POST-INFECTION TRAFFIC FROM UNIDENTIFIED RAT: - TCP port 443 - dns[.]google - secure DNS query (not malicious) - 89.124.79[.]98 port 443 - encoded or otherwise encrypted TCP traffic to C2 server for unidentified RAT
IMAGES

Shown above: SmartApeSG script injected into page from legitimate but compromised website.

Shown above: Fake CAPTCHA (human verification) page showing ClickFix instructions pasted into a run Window.

Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.
