2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS

NOTES:

ASSOCIATED FILE:

 

2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS

TRAFFIC TO SMARTAPESG DOMAIN FOR FAKE CAPTCHA/VERFICIATION PAGE:

- hxxps[:]//rowanportico[.]global/identity/realm-xml.js
- hxxps[:]//rowanportico[.]global/identity/role-template?xPM7XYCZ
- hxxps[:]//rowanportico[.]global/identity/secure-theme.js?18cddb5baf41fce0

URLS GENERATED BY RUNNING THE CLICKFIX TEXT:

- hxxp[:]//lagoonandledger[.]com/crol  <-- 302 redirect to HTTPS URL
- hxxps[:]//lagoonandledger[.]com/crol
- hxxp[:]//lagoonandledger[.]com/sepc  <-- 302 redirect to HTTPS URL
- hxxps[:]//lagoonandledger[.]com/sepc

POST-INFECTION TRAFFIC GENERATED BY THE INITIAL RAT:

- dns[.]google:443 - legitimate domain, likely used for DNS by the initial RAT
- 144.124.242[.]171:443 - encoded or otherwise encrypted TCP traffic (not HTTPS/TLS)

POST-INFECTION TRAFFIC CAUSED BY THE FOLLOW-UP RAT:

- hxxp[:]//5.252.177[.]69/  <- multiple HTTP POST requests over TCP port 80

ARTIFACTS FROM AN INFECTED WINDOWS HOST:

- C:\Users\[username]\AppData\Local\WERCCC.hta 
  -- File description: Initial download after running ClickFix text
- C:\Users\[username]\Documents\217417970796890430\217417970796890430.pdf
  -- File description: Zip archive containing files for legitimate program that side-loads DLL for initial RAT
- C:\Users\[username]\AppData\Local\setup.exe
  -- File description: Installer for follow-up RAT
- C:\ProgramData\872413f495df78d2a39228e6c9219ae7\
  -- Location description: Directory containing files for legitimate program that side-loads DLL for follow-up RAT

SHA256 HASHES:

- da2d68e10ea89c520623df66cb1b942914514cada6eb9720b5af9bd1fca502a5 - WERCCC.hta
- c99ddd0ba299b3e2c8e7d418e692fee6fa3ce773c24fb4b2e80aa6543e1f2f76 - 217417970796890430.pdf
- 883dce16fd4939efbd1296b8984ca67284a23503c9e63f43693f09c4aa5bad62 - setup.exe

REGISTRY UPDATE FOR PERSISTENCE OF INITIAL RAT:

Key Name:          HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Class Name:        
Last Write Time:   8/21/2026 - 3:29 PM

Value 0
  Name:            VAS Advanced Broker
  Type:            REG_SZ
  Data:            C:\Users\[username]\Documents\217417970796890430\VAssessment.exe

 

IMAGES


Shown above: SmartApeSG script injected into page from a legitimate website.

 


Shown above: Fake CAPTCHA/verification page generatted by the SmartApeSG traffic, showing the injected ClickFix text to paste into a Run window.

 


Shown above: Traffic from the infection filtered in Wireshark.

 

Click here to return to the main page.