The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Fake verification pages are steering people toward malware, but the web addresses behind the lures keep changing.

Over five months, investigators tracked four different attack chains that began with the same hosting network, even as domains, downloads and command servers shifted. The pattern makes blocking individual websites a poor way to stop the first step.

Most victims reached a fake CAPTCHA through online ads, although one arrived through an emailed link. The page quietly copied a command to the clipboard, then told the visitor to open the Windows Run box and paste it.

As with earlier fake CAPTCHA attacks, following those instructions could start an infection without opening a suspicious attachment.

Analysts from ActiveSOC identified the shared infrastructure while reviewing roughly 150 alerts across monitored environments.

ActiveSOC said in a report shared with Cyber Security News (CSN) that four cases reached command execution, while most contacts stopped at the lure page.

The findings describe a recurring entry point, not evidence that every visitor was infected, and this depicts that the consequences varied widely.

One chain installed a stealer that survived a reboot, while another placed a Node.js implant on a host and remained active for nearly two days.

A separate attempt contacted a cloud storage bucket but showed no confirmed second-stage installation, underscoring the gap between exposure and compromise.

The Domains Keep Disappearing

The common link was a hosting provider’s network registered in the Seychelles. Researchers saw at least seven entry addresses across six separate network ranges, and the provider expanded its announced space during the investigation.

Operators may have used the same service, but the evidence does not establish who controlled the campaigns. On one address alone, the researchers observed 12 lure domains in their telemetry and found 11 more in public scanning data.

The routes and chains that reached us (Source - ACTIVESOC)
The routes and chains that reached us (Source – ACTIVESOC)

Others used compromised retail or restaurant sites, echoing research on poisoned redirects, where the browser’s address bar showed a genuine website while an injected script supplied the fake challenge. That weakness makes simple domain checks unreliable.

This investigation highlights what stays put behind changing names and why removing one lure at a time changes little. Some pages even copied their host site’s name into the challenge, making the prompt appear to belong there.

One captured template mixed Windows instructions with a misspelled reference to a Mac feature. Once people pasted the command, the next step could come from the provider itself, a cloud bucket or an installer disguised as software.

installer placed a malicious library beside a legitimate application, a technique resembling software installer sideloading cases reported elsewhere. Those examples are context, not evidence that the separate campaigns share an operator.activesoc.blackhillsinfosec+1

Blocking the First Step

Speed mattered in one documented case: the browser reached the lure, and the user ran the pasted command 41 seconds later. An endpoint alert followed one second after execution.

Researchers could not tell whether protection stopped the next stage or the cloud bucket simply failed to deliver it, so they did not call that host compromised.

Other chains were harder to follow after the initial page. One implant retrieved its command server through a blockchain lookup rather than a conventional domain, an approach explained in blockchain based command control reporting.

The lure as the user sees it (Source - ACTIVESOC)
The lure as the user sees it (Source – ACTIVESOC)

This is why stopping the lure does not replace monitoring for activity already running on a device. ActiveSOC recommends checking an organization’s own outbound traffic before blocking the provider’s network, because another environment could rely on an address there.

Then block the network’s announced ranges, keep logs of denied connections and refresh the range list. A fixed list can miss newly added space or block addresses that have changed hands.

Defenders should also watch for browsers handing off to command interpreters, unsigned libraries beside signed software, and trusted runtimes launched from user writable folders.

Suspicious ads deserve attention, but an alert on a page visit alone does not prove malware ran. Teach users that a website asking them to paste a clipboard command into the Run box is not performing a verification.

Indicators of compromise (IoCs):-

Type Indicator Description
ASN AS202412 Shared entry-point hosting network. Check local traffic and current announcements before blocking.activesoc.blackhillsinfosec
IP address 178.16.52[.]101 Lure host linked to observed and publicly scanned domains.
IP address 178.16.53[.]137 Injected-script and advertising redirect host.
IP address 158.94.211[.]92 In-memory payload staging host.
IP address 158.94.208[.]213 Lure host in the 41-second case.
IP address 158.94.208[.]104 Browser contact.
IP address 91.92.243[.]161 Browser contact; no lure domain recovered.
IP address 178.16.54[.]253 Lure host; also hosted an unrelated site.
IP address 178.16.54[.]40 Outbound contact.
IP address 178.16.55[.]232 Outbound contact.
IP address 91.92.241[.]111 Outbound contact.
IP address 158.94.211[.]76 Outbound contact.
IP address 130.12.180[.]63 Lure host reached through an emailed short link.
IP address 130.12.180[.]174 Outbound contact.
IP address 91.92.240[.]127 Script source recovered in a sandbox, not observed on a monitored host.
IP address 16.15.228[.]38 Cloud storage endpoint used in the timeline; not attacker-owned and should not be blocked solely on this basis.
IP address 193.202.84[.]17 Primary command server and data sink.
IP address 176.65.144[.]127 Blockchain-resolved command server observed on TCP port 3847; assess all ports.
Network range 91.92.240[.]0/24 Provider range containing the sandbox-observed script source.
Network range 130.12.180[.]0/24 Range blocked during the emailed-link response; verify current ownership.
Network range 172.111.246[.]0/24 Additional range the provider announced during observation; verify current ownership.
Domain auth-id-browser[.]info Lure domain observed resolving to the shared host.
Domain enter-code-cdn[.]info Lure domain observed resolving to the shared host.
Domain authorization-cdn-press-enter[.]info Lure domain observed resolving to the shared host.
Domain enter-press-cdn[.]info Lure domain observed resolving to the shared host.
Domain authorization-code[.]info Lure domain observed resolving to the shared host.
Domain enter-pverif-code[.]info Lure domain observed resolving to the shared host.
Domain clacndjsvulnarbi[.]beer Lure domain observed resolving to the shared host.
Domain fingerprint-verification[.]info Lure domain observed resolving to the shared host.
Domain clnsdns[.]beer Lure domain observed resolving to the shared host.
Domain framework-css-styles-js[.]beer Lure domain observed resolving to the shared host.
Domain codeverificatrorcl[.]info Lure domain observed resolving to the shared host; also seen prepared in advance.
Domain idverification-code[.]beer Lure domain observed resolving to the shared host.
Domain fraudtechnology[.]com Related name not observed resolving in monitored environments.
Domain auth-code-check[.]info Related name not observed resolving in monitored environments.
Domain id-verif-code[.]info Related name not observed resolving in monitored environments.
Domain enter-press-code[.]info Related name not observed resolving in monitored environments.
Domain authorization-press-enter[.]info Related name not observed resolving in monitored environments.
Domain capcha-cdn-js[.]beer Related name not observed resolving in monitored environments.
Domain fingerprint-veri[.]info Additional name found in public scans, not observed on monitored hosts.
Domain verico-de-id[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain bootstrap-maxcdn[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain trunnsns[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain ai-nexora[.]sbs Additional name found in public scans, not observed on monitored hosts.
Domain chekbrow[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain cdn-plugin-js[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain lcates-vs[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain bnsclod[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain biyaconserver[.]beer Additional name found in public scans, not observed on monitored hosts.
Domain cdn-2faclov[.]sbs Additional name found in public scans, not observed on monitored hosts.
Domain catholicsma[.]com Lure serving a padded Run-box command.
Domain rsvpopenh[.]one Lure reached through an emailed short link.
Domain marketing080company[.]one Lure resolving to the provider’s network.
Domain thegreenfortune[.]com Lure domain.
Domain mnoskemp[.]beer Archive utility and payload archive host.
Domain pilotkadomen[.]club Recovered second-stage download destination; execution was not observed.
Domain claritydelivr[.]com Newly registered staging-related parent domain.
Domain cdn.claritydelivr[.]com Script host in one setting and stager front in another.
Domain approvalrequest-api[.]com Installer source in a pasted command.
Domain 2d4e5f6-7a8b-4c2d-9e1f-3b5a7c8d9e0fc.s3.us-east-1.amazonaws[.]com First-stage batch-script host as transcribed in the source; confirm its unusual label before pivoting.
Domain lockpopclickgetfile[.]monster Payload-delivery domain.
Domain pipeplane[.]cfd Delivery host.
Domain pcapps[.]my Delivery domain using random subdomains.
Domain gettrack[.]my Delivery domain using random subdomains.
Domain securecab[.]fit Delivery domain using random subdomains.
Domain uruvita[.]com Delivery domain.
Domain unhosting[.]site Delivery domain associated with a 32-hex-character subdomain pattern.
Domain dntds[.]shop Traffic-distribution name.
Domain nttdss[.]shop Traffic-distribution name.
Domain sdntds[.]shop Traffic-distribution name.
Domain ntdnewtds[.]shop Traffic-distribution name also present in script failover.
Domain dnsnewtds[.]shop Traffic-distribution name also present in script failover.
Domain newtdsone[.]shop Traffic-distribution name.
Domain alianzeg[.]shop Traffic-distribution name.
Domain getfix[.]win Historical TLS certificate subject.
Domain carrotbunnies[.]com Stealer command domain resolving to the listed data-sink address.
Domain kerosand[.]net Blockchain-resolved command domain.
Domain shorturl[.]at Legitimate shortening service used as an emailed-link wrapper; not an attacker-owned domain.
URL path /jsrepo Injected-script endpoint on the redirect host.
URL path /teamrepo Injected-script endpoint on the redirect host.
URL pattern http://approvalrequest-api[.]comcaph.php?token=<redacted> Installer URL as shown in the source command, including its unusual backslash and redacted token.
SHA-256 9a736f4812b485f9cf5b1332a791b205b5135a4b3a0c41f473ad9cc9fbe2d75c MSI dropper.
SHA-256 b004acacd8ef5d7e8a2fd99a7931af0ced87b280d5acd2fde499da4a8f24e916 Trojanized obs.dll.
SHA-256 81ecbf004dc9dbf8ea4c50bde1ed55806fb5fdf689d165856112ea9f4d5021e0 WSql-2.dll.
SHA-256 a410c89db9140ed9dff55bff00b0338fbdffcc709490782c7b28e8a10c11eb3b cred64.dll plugin; cited from upstream intelligence rather than a chain ActiveSOC investigated.
SHA-256 d77bc0bb3018b6cc834c1af1eefaa1c0b906314308d6ab88588f8d41eb62090c cmd.cmd loader; cited from upstream intelligence rather than a chain ActiveSOC investigated.
MSI product code {C5907138-B44F-408E-A9CA-4D49FDEBD5AC} Installer product code that remained stable when filenames changed.
File path %LOCALAPPDATA%ProgramsOBS Studio Enhanced Controller Trojanized install directory.
File path %LOCALAPPDATA%HostSharednode.exe Implant runtime location; assess with its script and launch context.
File path appsrcindex.js Script executed by the implant runtime.
File path %LOCALAPPDATA%Microsoft Embedded Python runtime and extraction-tool drop location.
File path %LOCALAPPDATA%Temp Randomly named archive staging directory.
Registry path HKLMSOFTWAREMicrosoftActive SetupInstalled Components Persistence location used with a StubPath entry.
Process pattern conhost.exe --headless cmd /c, parented by Explorer.EXE Observed pasted-command execution pattern; not suspicious without context.
File name obs.dll Trojanized library loaded by a legitimate application.
File name obs64.exe Legitimate signed executable used to load the malicious library; not malicious alone.
File name WSql-2.dll Nonstandard bundled library; not seen loading in the observed host window.
File name tessnet2.dll Metadata name forged inside WSql-2.dll.
File name RegisterIdr.dll Nonstandard library seen in sandbox behavior, not on the monitored host.
File name 7za.exe Standalone extraction utility renamed during delivery; not malicious alone.
File name ._agent.vbs Hidden script dropped beside the implant runtime.
File name config.cmd First-stage cloud-hosted batch script.
File name config.py Later-stage script fetched from the same bucket.
File name node.exe Signed runtime used by the implant; filename alone is not an indicator.
Archive password popsa Password for the delivered archive.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves appeared first on Cyber Security News.