home.social

#clearfake — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.

fetched live
  1. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  2. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  3. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  4. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  5. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  6. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  7. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  8. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  9. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  10. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  11. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  12. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  13. Вредоносный код навсегда сохранили в блокчейне

    Один из старых хакерских трюков — распространять вредоносное ПО под видом обновления браузера . На взломанном сайте размещается плашка с утверждением, что для просмотра нужно обновить браузер. И кнопка для скачивания обновления, как на скриншоте с прошлогодней атаки ClearFake . Таким образом, жертва самостоятельно устанавливает вредоносное ПО на свой компьютер. В прошлом году злоумышленники разработали умный способ защитить вредоносный софт от уничтожения. Они разместили его в децентрализованном анонимном блокчейне . То есть интегрировали код в смарт-контракт, который навечно сохранился в открытом доступе.

    habr.com/ru/companies/globalsi

    #блокчейн #обновление_браузера #BSC #Binance_Smart_Chain #Binance #BNB #WordPress #ClearFake #BscScan #EtherHiding

  14. #ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer

  15. #ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer

  16. New Swiss centered malware campaign in German using some #ClearFake / #ClickFix tricks impersonating Ricardo, one of the biggest Swiss online second-hand marketplace:

  17. New Swiss centered malware campaign in German using some #ClearFake / #ClickFix tricks impersonating Ricardo, one of the biggest Swiss online second-hand marketplace:

  18. @monitorsg #ClearFake is back to fake browser updates. The EXE leads to a Lumma stealer that appears to use these domains.

    predatowpmn[.]shop
    preachstrwnwjw[.]shop
    pang-scrooge-carnage[.]shop

    h/t @GustyDusty

  19. @monitorsg #ClearFake is back to fake browser updates. The EXE leads to a Lumma stealer that appears to use these domains.

    predatowpmn[.]shop
    preachstrwnwjw[.]shop
    pang-scrooge-carnage[.]shop

    h/t @GustyDusty

  20. Sometimes people ask us to remove a domain from our blocklists that are part of a malicious traffic distribution system (TDS) because they "visited the url" and didn't get malware. This is like saying "I walked past the armed robber and didn't get robbed." Count yourself lucky. Say no to TDS. #dns #threatintel #cybercrime #malware #phishing #scam #infoblox #cybersecurity #infosec #tds #vextrio #socgholish #clearfake #404tds #adware

  21. Sometimes people ask us to remove a domain from our blocklists that are part of a malicious traffic distribution system (TDS) because they "visited the url" and didn't get malware. This is like saying "I walked past the armed robber and didn't get robbed." Count yourself lucky. Say no to TDS. #dns #threatintel #cybercrime #malware #phishing #scam #infoblox #cybersecurity #infosec #tds #vextrio #socgholish #clearfake #404tds #adware

  22. #ClearFake related contract 0xa6165aa33ac710ad5dcd4f4d6379466825476fde was updated recently and points now to daslkjfhi2[.]lol, displaying a new type of lure to visitors:

  23. #ClearFake related contract 0xa6165aa33ac710ad5dcd4f4d6379466825476fde was updated recently and points now to daslkjfhi2[.]lol, displaying a new type of lure to visitors:

  24. @cyberamateur your recently documented #clearfake pattern infosec.exchange/@cyberamateur seems to have changed again.

    I double-checked how the new TDS b9y3b7ner2[.]xyz behaves. What I got seems to be a work-in-progress powershell script. From my partial understanding of the code so far:
    - A new Binance contract is involved: 0xc12d0ca65b8bc87265b33c13bab479e5d91cc08e
    - Depending on how you interact with this contract, you may get the AES encrypted value of the C2 domain, or some further payload to execute
    - The key of the AES decryption is within the script itself
    - The IV comes from https://rentry[.]co/t5266q3p/raw

    Based upon this manual analysis, the C2 appears to be hXXps://rsmbscm.wikilogistics[.]wiki/post.php

  25. @cyberamateur your recently documented #clearfake pattern infosec.exchange/@cyberamateur seems to have changed again.

    I double-checked how the new TDS b9y3b7ner2[.]xyz behaves. What I got seems to be a work-in-progress powershell script. From my partial understanding of the code so far:
    - A new Binance contract is involved: 0xc12d0ca65b8bc87265b33c13bab479e5d91cc08e
    - Depending on how you interact with this contract, you may get the AES encrypted value of the C2 domain, or some further payload to execute
    - The key of the AES decryption is within the script itself
    - The IV comes from https://rentry[.]co/t5266q3p/raw

    Based upon this manual analysis, the C2 appears to be hXXps://rsmbscm.wikilogistics[.]wiki/post.php

  26. #ClearFake updated the TDS in contract 0x34585777843Abb908a1C5FbD6F3f620bC56874AA 3 times today:
    v7yen47u2e[.]xyz
    cv2b8uz46e[.]xyz
    b9y3b7ner2[.]xyz (currently used)

    The last round of updates on this contract was on May 30th - also with 3 different domains.

  27. #ClearFake has updated what it gets the end user to copy/paste into Powershell. The new code has a touch more obfuscation. ipconfig /flushdns is now base64'd. It uses variable names like $ERROR_FIX to appear like maybe it actually is to fix a problem.

    It also has a new stats feature. It will send a POST to here presumably so it knows that a user ran the initial script.

    stats.drinkresources[.]rest
  28. Put out a fresh analysis of #ClearFake. It has some new features.

    • A fake “How to fix” user experience
    • Instead of a download, they convince the user to copy/paste malicious Powershell
    • Very curious delayed 2-10 day go-live for infected websites

    rmceoin.github.io/malware-anal

    #ThreatIntel

  29. #ClearFake contract 0x34585777843Abb908a1C5FbD6F3f620bC56874AA is now updated automatically every 10 minutes, altering the used variable names. Let's see if more changes come soon... bscscan.com/address/0x34585777