```html ```
top of page

ClearFake Now Runs Through a Cloudflare Worker, Pulls Its Config Off the BNB Chain, and Executes a DLL Over WebDAV. Free Feeds Had 37% of It in March. The Three Smart Contracts Were in Nobody's.

Writer: Patrick Duggan
Patrick Duggan
3 minutes ago
5 min read

Cisco Talos published the full anatomy of a ClearFake infection chain on September 8, and it is worth reading slowly, because every stage is a place your defenses were not designed to look. Then we ran all 79 of Talos's indicators against our corpus. Twenty-nine were already there, some since March, every one of them from a free public feed. The three that no feed anywhere carried are the ones that make the whole chain work.



The chain, stage by stage


A compromised website gets a malicious Cloudflare Worker injected in front of it. The Worker, not the site, serves the ClearFake JavaScript. That JavaScript queries a contract on the BNB Smart Chain testnet, address 0x886d310Ac23e05EA705e24E513D19f53793832A9, and receives an operating-system-specific pointer; on Windows it goes to a second contract, 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff, for the payload. This is EtherHiding: the config lives on a blockchain, which nobody can take down and few people log.


The victim sees a fake Google CAPTCHA that tells them to paste a command. The command is rundll32.exe pointed at a UNC path on a WebDAV server: \\leaguejazire.com\<random>\<victim-id>\pf.ch. The 32-bit rundll32 fetches the DLL over WebDAV and invokes ordinal 1. No download in the browser. No file the user chose to save. The loader runs from a network share that happens to be on the internet.


From there, two branches. The pf.ch loader drops Amatera stealer build 4.1.5-alpha, which resolves its C2 through a telegra.ph dead-drop page and lands on 145.249.109.147, then a NativeAOT loader running ZigCryptoStealer, which polls the clipboard and swaps cryptocurrency addresses and resolves its own C2 through a third BNB contract, 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468, plus a Go reverse proxy speaking WebSocket to update.dubbedmuch.cc with Yamux multiplexing. The verification.google loader drops Amatera with a fixed C2 at 45.150.34.2 behind a TLS SNI of github.com, then a fileless PowerShell install of NetSupport Manager pointed at a Russian gateway, 212.118.56.166, using a license key Talos has seen in the EVALUSION and IClickFix campaigns. Talos tracks that branch as UAT-10820 and assesses it as Russian with moderate confidence. Amatera's config carries 400-plus collection targets, over a hundred wallet locations, and every password manager you have heard of.





What free feeds already had, and when


We hold 29 of Talos's 79 indicators, and none of them are ours. They came in through the feeds we redistribute, and their dates are the point.


Spamhaus's SSL Blacklist had both Amatera C2 IPs, 45.150.34.2 and 150.241.94.112, on March 19, and 145.249.109.147 on May 1. It had the telegra.ph dead-drop URL on March 23. It had paf.hugo-mapp.co and smart.hugo-mapp.co on April 4, tnt.unguidedfreewill.co on April 6, and fd-api-irs.velqo7.co on April 17. Talos says the chain was first observed in April. SSLBL had the C2 layer before the chain was.


ThreatFox and URLhaus had the WebDAV host leaguejazire.com on June 11 and riyazinikokar.xyz on June 17. ThreatFox had the ZigCryptoStealer C2 hosts through July: kffd3.vogueatelier.cc on the 16th, mgo.gstats-api-contact.cc on the 15th, static.quorashift.cc on the 25th, lb.propertyfind.cc on the 29th. URLhaus had the estimator-undermostshelving.in.net staging on July 27. Four of the 22 hashes were in MalwareBazaar or ThreatFox before Talos published; three landed the day after.


So a defender who consumes SSLBL, ThreatFox and URLhaus directly, or who pulls our blocklists, which carry all three, had 37 percent of this chain blocked, including every Amatera C2 address, months before there was a write-up to read. That is not our lead and we will not dress it as one. It is the free feeds' lead, and the value we add is that a school IT department that has never heard of SSLBL gets it in one curl. The remaining 50 indicators, including the WebDAV loader hashes, the NetSupport gateway, the reverse-proxy WebSocket endpoint, and 30-odd C2 subdomains, are in the feed tonight under a campaign-specific source, attributed to ClearFake and UAT-10820, with Talos as the reference.



The three that were in nobody's feed


The three BNB Smart Chain contract addresses were not in our corpus, and they are not in ThreatFox, URLhaus, SSLBL or MalwareBazaar either, because those feeds do not have a type for them. Neither does STIX, cleanly. A contract address is not a domain, an IP, a URL or a hash. It is the one piece of this chain that cannot be sinkholed, cannot be taken down, and does not rotate, which makes it the most durable indicator in the whole write-up and the one the industry's formats are worst at carrying.


We added a chain-address type to our feed in August, after a dead-drop campaign taught us the same lesson, and the three ClearFake contracts went in tonight under that type. Our MISP export degrades it to a text attribute with to_ids false rather than forcing it into a wrong type, because a mislabeled attribute becomes a bad IDS rule on somebody else's network. If you run an EDR or proxy that can match on outbound JSON-RPC calls to BSC endpoints, the contract addresses are the thing to alert on. Blocking the RPC endpoints themselves is a blunter instrument and will break legitimate wallets.



Two things worth sitting with


First, the attacker's front end is a Cloudflare Worker. So is our edge shield. The same platform that lets us put a threat-intel blocklist in front of a website for free lets an attacker put a payload injector in front of a compromised one. The compromised site's owner sees nothing in their own code because the code is not in their site. If you are responsible for a WordPress or similar site, the Cloudflare dashboard's Workers Routes page is now part of your attack surface review.


Second, the delivery is WebDAV over rundll32. There is no browser download event, no Mark-of-the-Web, no file for a user to double-click. The detection is process telemetry: a 32-bit rundll32.exe whose command line contains a UNC path to an internet host, invoking ordinal 1. If your EDR cannot show you that, you cannot see this chain at all.



Where we stand


We own the ClearFake beat: our first-party catch of the Apothecary rotation domains in May, and the sibling hunter that watches numbered ClearFake hosts every morning. On this specific chain we have no first-party receipt; every indicator we held came from a feed, and the earliest dates belong to Spamhaus. Talos did the work. What we add is the redistribution, the attribution in the feed, the three contract addresses as a first-class indicator type, and the timeline that shows the C2 layer was public five months before the anatomy was.




Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=clearfake-now-runs-through-a-cloudflare-worker-pulls-its-config-off-the-bnb-chain-and-executes-a-d



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page