2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS
NOTES:
- Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.
ASSOCIATED FILE:
- 2026-08-21-SmartApeSG-ClickFix-notes.txt.zip 1.6 kB (1,570 bytes)
- 2026-08-21-SmartApeSG-and-traffic-from-two-different-RATs.pcap.zip 47.7 MB (47,730,265 bytes)
- 2026-08-21-files-from-the-infection.zip 26.9 MB (26,887,968 bytes)
2026-08-21 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN LEADS TO TWO RATS TRAFFIC TO SMARTAPESG DOMAIN FOR FAKE CAPTCHA/VERFICIATION PAGE: - hxxps[:]//rowanportico[.]global/identity/realm-xml.js - hxxps[:]//rowanportico[.]global/identity/role-template?xPM7XYCZ - hxxps[:]//rowanportico[.]global/identity/secure-theme.js?18cddb5baf41fce0 URLS GENERATED BY RUNNING THE CLICKFIX TEXT: - hxxp[:]//lagoonandledger[.]com/crol <-- 302 redirect to HTTPS URL - hxxps[:]//lagoonandledger[.]com/crol - hxxp[:]//lagoonandledger[.]com/sepc <-- 302 redirect to HTTPS URL - hxxps[:]//lagoonandledger[.]com/sepc POST-INFECTION TRAFFIC GENERATED BY THE INITIAL RAT: - dns[.]google:443 - legitimate domain, likely used for DNS by the initial RAT - 144.124.242[.]171:443 - encoded or otherwise encrypted TCP traffic (not HTTPS/TLS) POST-INFECTION TRAFFIC CAUSED BY THE FOLLOW-UP RAT: - hxxp[:]//5.252.177[.]69/ <- multiple HTTP POST requests over TCP port 80 ARTIFACTS FROM AN INFECTED WINDOWS HOST: - C:\Users\[username]\AppData\Local\WERCCC.hta -- File description: Initial download after running ClickFix text - C:\Users\[username]\Documents\217417970796890430\217417970796890430.pdf -- File description: Zip archive containing files for legitimate program that side-loads DLL for initial RAT - C:\Users\[username]\AppData\Local\setup.exe -- File description: Installer for follow-up RAT - C:\ProgramData\872413f495df78d2a39228e6c9219ae7\ -- Location description: Directory containing files for legitimate program that side-loads DLL for follow-up RAT SHA256 HASHES: - da2d68e10ea89c520623df66cb1b942914514cada6eb9720b5af9bd1fca502a5 - WERCCC.hta - c99ddd0ba299b3e2c8e7d418e692fee6fa3ce773c24fb4b2e80aa6543e1f2f76 - 217417970796890430.pdf - 883dce16fd4939efbd1296b8984ca67284a23503c9e63f43693f09c4aa5bad62 - setup.exe REGISTRY UPDATE FOR PERSISTENCE OF INITIAL RAT: Key Name: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Class Name:Last Write Time: 8/21/2026 - 3:29 PM Value 0 Name: VAS Advanced Broker Type: REG_SZ Data: C:\Users\[username]\Documents\217417970796890430\VAssessment.exe
IMAGES

Shown above: SmartApeSG script injected into page from a legitimate website.

Shown above: Fake CAPTCHA/verification page generatted by the SmartApeSG traffic, showing the injected ClickFix text to paste into a Run window.

Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.
