#clearfake — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a8c4d5527ae029719473a8b
Pulse Link: https://otx.alienvault.com/pulse/6a8c4d5527ae029719473a8b
Pulse Author: CyberHunter_NL
Created: 2026-08-24 13:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a8c4d5527ae029719473a8b
Pulse Link: https://otx.alienvault.com/pulse/6a8c4d5527ae029719473a8b
Pulse Author: CyberHunter_NL
Created: 2026-08-24 13:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a8c4d5527ae029719473a8b
Pulse Link: https://otx.alienvault.com/pulse/6a8c4d5527ae029719473a8b
Pulse Author: CyberHunter_NL
Created: 2026-08-24 13:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a8c4d5527ae029719473a8b
Pulse Link: https://otx.alienvault.com/pulse/6a8c4d5527ae029719473a8b
Pulse Author: CyberHunter_NL
Created: 2026-08-24 13:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a8c4d5527ae029719473a8b
Pulse Link: https://otx.alienvault.com/pulse/6a8c4d5527ae029719473a8b
Pulse Author: CyberHunter_NL
Created: 2026-08-24 13:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL
-
WordlistLoader malware delivers Amatera Stealer through ClearFake fake-CAPTCHA campaigns, using stealthy evasion to steal browser data.
#WordlistLoader #AmateraStealer #ClearFake #ClickFix #InfoStealer
-
WordlistLoader malware delivers Amatera Stealer through ClearFake fake-CAPTCHA campaigns, using stealthy evasion to steal browser data.
#WordlistLoader #AmateraStealer #ClearFake #ClickFix #InfoStealer
-
WordlistLoader malware delivers Amatera Stealer through ClearFake fake-CAPTCHA campaigns, using stealthy evasion to steal browser data.
#WordlistLoader #AmateraStealer #ClearFake #ClickFix #InfoStealer
-
Hackers Hide Malware Code Inside English Words to Infect Windows Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a86f988170e8cbccf5ad369
Pulse Link: https://otx.alienvault.com/pulse/6a86f988170e8cbccf5ad369
Pulse Author: CyberHunter_NL
Created: 2026-08-20 12:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL
-
Hackers Hide Malware Code Inside English Words to Infect Windows Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a86f988170e8cbccf5ad369
Pulse Link: https://otx.alienvault.com/pulse/6a86f988170e8cbccf5ad369
Pulse Author: CyberHunter_NL
Created: 2026-08-20 12:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL
-
Hackers Hide Malware Code Inside English Words to Infect Windows Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a86f988170e8cbccf5ad369
Pulse Link: https://otx.alienvault.com/pulse/6a86f988170e8cbccf5ad369
Pulse Author: CyberHunter_NL
Created: 2026-08-20 12:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL
-
Hackers Hide Malware Code Inside English Words to Infect Windows Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a86f988170e8cbccf5ad369
Pulse Link: https://otx.alienvault.com/pulse/6a86f988170e8cbccf5ad369
Pulse Author: CyberHunter_NL
Created: 2026-08-20 12:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL
-
Hackers Hide Malware Code Inside English Words to Infect Windows Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns
Pulse ID: 6a86f988170e8cbccf5ad369
Pulse Link: https://otx.alienvault.com/pulse/6a86f988170e8cbccf5ad369
Pulse Author: CyberHunter_NL
Created: 2026-08-20 12:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL
-
📢 Dropcatch : trois acteurs scavengers recyclent des domaines malveillants expirés pour monétiser du trafic
📅 Source : Infoblox Threat Intelligence, publié le 13 août 2026. Il s'agit de la troisième partie d'une série de blogs sur la pratique du dropcatch de domaines malveillants. Chaque année, des dizaines de milliers de sites web sont compromis par…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-dropcatch-trois-acteurs-scavengers-recyclent-des-domaines-malveillants-expires-pour-monetiser-du-trafic/
🌐 source : https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
🟢 vérification factuelle haute
#dropcatch #ClearFake #Cyberveille -
-
-
-
-
-
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 New malware variant: ClickFix
Guardio Labs reveals a ClearFake mutation that skips downloads and uses fake CAPTCHAs to get users to paste malware into Run or Terminal.
▪️ Cross-platform
▪️ Google Scripts abused
▪️ Hosted payloads in JS files
▪️ SEO & drive-by lures“A chilling list of techniques…” — Shaked Chen
#clickfix #ClearFake #CAPTCHAgeddon #Malware #GuardioLabs #CyberThreat #Infosec #MastodonSec
-
🚨 New malware variant: ClickFix
Guardio Labs reveals a ClearFake mutation that skips downloads and uses fake CAPTCHAs to get users to paste malware into Run or Terminal.
▪️ Cross-platform
▪️ Google Scripts abused
▪️ Hosted payloads in JS files
▪️ SEO & drive-by lures“A chilling list of techniques…” — Shaked Chen
#clickfix #ClearFake #CAPTCHAgeddon #Malware #GuardioLabs #CyberThreat #Infosec #MastodonSec
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇