🔍 Contexte
Publié le 8 septembre 2026 par Cisco Talos (blog.talosintelligence.com), cet article présente une analyse technique approfondie de deux chaînes d’infection parallèles découvertes après l’observation en avril 2026 d’une exécution de DLL via WebDAV dans la télémétrie d’une organisation gouvernementale ukrainienne.
🎯 Vecteur initial et mécanisme de livraison
Les deux chaînes reposent sur un Cloudflare Worker malveillant injectant du JavaScript dans des sites compromis. Ce code interroge des contrats BNB Smart Chain (technique EtherHiding) pour récupérer du code JavaScript encodé, puis affiche une fausse vérification Google CAPTCHA (ClickFix) incitant la victime à exécuter une commande via la boîte de dialogue Windows Run. La commande ouvre un chemin WebDAV et exécute une DLL déguisée via rundll32.exe par ordinal #1.
🧩 Deux chaînes, deux loaders
- Loader “pf.ch” : DLL 32 bits packée utilisant la gestion d’exceptions vectorisées (VEH), XOR, LZNT1, API hashing. Charge Amatera 4.1.5-alpha en mémoire. Résout son C2 via une page Telegraph (
telegra.ph/Functions-04-03) encodant l’IP145.249.109.147. - Loader “verification.google” : DLL utilisant DLL hollowing sur
dbghelp.dll, syscalls WoW64 directs, TpAllocWork pour exécution asynchrone. Charge Amatera avec C2 fixe45.150.34.2, se présentant commegithub.comen TLS SNI.
💀 Payloads secondaires
Branche pf.ch :
- ZigCryptoStealer : stealer en langage Zig, clipper de cryptomonnaies, utilise EtherHiding (contrat
0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468) pour récupérer son domaine C2. Chargé via DLL side-loading d’un composant Chrome légitime (platform_experience_helper.exe) sideloadantSecur32.dll(NativeAOT loader). - Driver BYOVD (
DCRCVDrv.sys) : driver signé vulnérable utilisé pour terminer les processus EDR via IOCTL0x2205c0. - Go reverse TCP proxy : exécutable Go 32 bits (
github.com/acr/proxy-panel/cmd/bot), communication via WebSocket Secure avec multiplexage Yamux, C2wss://update.dubbedmuch.cc.
Branche verification.google :
- NetSupport Manager 12.44 (renommé
hypersnap.exe) installé silencieusement via PowerShell, gateway C2paternal-angrily.com:443résolvant vers212.118.56.166(Russie). Licence KAKAN / NSM789508 liée à des activités EVALUSION et IClickFix.
🌐 Attribution
- L’acteur derrière la branche “verification.google” est tracké comme UAT-10820, évalué avec une confiance modérée comme étant un acteur russophone.
- Les attaques sont évaluées comme non ciblées, s’inscrivant dans une opération de vol de cryptomonnaies et de credentials.
📊 Portée
Le domaine ZigCryptoStealer lb.propertyfind.cc a généré des requêtes DNS depuis 98 pays, avec une concentration aux États-Unis, Indonésie, Brésil, Inde et Égypte.
📄 Nature de l’article
Il s’agit d’une analyse technique détaillée publiée par Cisco Talos, visant à documenter les chaînes d’infection, les TTPs, les IOCs et les payloads associés à des campagnes actives de vol de données et de cryptomonnaies.
🧠 TTPs et IOCs détectés
Acteurs de menace
- UAT-10820 (cybercriminal) —
TTP
- T1566 — Phishing (Initial Access)
- T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
- T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
- T1218.011 — System Binary Proxy Execution: Rundll32 (Defense Evasion)
- T1574.002 — Hijack Execution Flow: DLL Side-Loading (Defense Evasion)
- T1055.001 — Process Injection: Dynamic-link Library Injection (Defense Evasion)
- T1620 — Reflective Code Loading (Defense Evasion)
- T1562.001 — Impair Defenses: Disable or Modify Tools (Defense Evasion)
- T1027 — Obfuscated Files or Information (Defense Evasion)
- T1102 — Web Service (Command and Control)
- T1568 — Dynamic Resolution (Command and Control)
- T1219 — Remote Access Software (Command and Control)
- T1090 — Proxy (Command and Control)
- T1539 — Steal Web Session Cookie (Credential Access)
- T1555 — Credentials from Password Stores (Credential Access)
- T1025 — Data from Removable Media (Collection)
- T1115 — Clipboard Data (Collection)
- T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1053.005 — Scheduled Task/Job: Scheduled Task (Persistence)
- T1497 — Virtualization/Sandbox Evasion (Defense Evasion)
- T1082 — System Information Discovery (Discovery)
- T1057 — Process Discovery (Discovery)
- T1105 — Ingress Tool Transfer (Command and Control)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
IOC
- IPv4 :
145.249.109.147— AbuseIPDB · VT · ThreatFox - IPv4 :
45.150.34.2— AbuseIPDB · VT · ThreatFox - IPv4 :
212.118.56.166— AbuseIPDB · VT · ThreatFox - Domaines :
leaguejazire.com— VT · URLhaus · ThreatFox - Domaines :
riyazinikokar.xyz— VT · URLhaus · ThreatFox - Domaines :
bsc-testnet-rpc.publicnode.com— VT · URLhaus · ThreatFox - Domaines :
bsc.rpc.blxrbdn.com— VT · URLhaus · ThreatFox - Domaines :
lb.propertyfind.cc— VT · URLhaus · ThreatFox - Domaines :
fd.gstats-api-contact.cc— VT · URLhaus · ThreatFox - Domaines :
pkg.vogueatelier.cc— VT · URLhaus · ThreatFox - Domaines :
kffd3.vogueatelier.cc— VT · URLhaus · ThreatFox - Domaines :
kffd3.vexlatech.cc— VT · URLhaus · ThreatFox - Domaines :
static.quorashift.cc— VT · URLhaus · ThreatFox - Domaines :
update.dubbedmuch.cc— VT · URLhaus · ThreatFox - Domaines :
kr.cedar2glanz.ru— VT · URLhaus · ThreatFox - Domaines :
paternal-angrily.com— VT · URLhaus · ThreatFox - Domaines :
phys.stunned-amniotic.com— VT · URLhaus · ThreatFox - Domaines :
telegra.ph— VT · URLhaus · ThreatFox - URLs :
https://telegra.ph/Functions-04-03— URLhaus - URLs :
https://kr.cedar2glanz.ru/jewel.js— URLhaus - URLs :
https://phys.stunned-amniotic.com/hub.log— URLhaus - URLs :
wss://update.dubbedmuch.cc/— URLhaus - SHA256 :
279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92— VT · MalwareBazaar - SHA256 :
643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205— VT · MalwareBazaar - SHA256 :
1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25— VT · MalwareBazaar - SHA256 :
bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b— VT · MalwareBazaar - Fichiers :
verification.google - Fichiers :
pf.ch - Fichiers :
secur32.dll - Fichiers :
Secur32.dll - Fichiers :
DCRCVDrv.sys - Fichiers :
platform_experience_helper.exe - Fichiers :
hypersnap.exe - Fichiers :
client32.exe - Fichiers :
PCICL32.DLL - Fichiers :
client32.ini - Fichiers :
jquery.min.js - Fichiers :
hub.log - Chemins :
%APPDATA%
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 10 septembre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- Amatera Stealer (stealer)
- ZigCryptoStealer (stealer)
- NetSupport Manager (rat)
- ClearFake (framework)
- NativeAOT Loader (loader)
- Go Reverse TCP Proxy (tool)
- DCRCVDrv.sys (tool)
🟢 Indice de vérification factuelle : 95/100 (haute)
- ✅ blog.talosintelligence.com — source reconnue (liste interne) (20pts)
- ✅ 29407 chars — texte complet (fulltext extrait) (15pts)
- ✅ 39 IOCs dont des hashes (15pts)
- ✅ 9/12 IOCs confirmés (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 24 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ✅ acteur(s) identifié(s) : UAT-10820 (5pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
145.249.109.147(ip) → VT (11/89 détections) + ThreatFox (Unknown malware)45.150.34.2(ip) → VT (11/89 détections) + ThreatFox (ACR Stealer)212.118.56.166(ip) → VT (4/89 détections)279d04c0cfd700c8…(sha256) → VT (47/76 détections) + ThreatFox (Amatera)643ef35536ff9273…(sha256) → ThreatFox (Amatera)
🔗 Source originale : https://blog.talosintelligence.com/clearfake-webdav-infection-chain/