PULSE NAME
HelloTDS: The Infrastructure Behind FakeCaptcha
WHITE PetrP.73 2025-06-11 Modified: 2025-07-11
897
IOCs
HIGH VOLUME
The analysis of the HelloTDS infrastructure reveals a complex Traffic Direction System (TDS) that facilitates various malware campaigns, including FakeCaptcha, by exploiting vulnerable websites and malvertising techniques. HelloTDS operates through a robust network that utilizes geolocation, IP address, and browser fingerprinting to determine the nature of content delivered to users. It particularly targets users through compromised streaming sites and file-sharing services that have been manipulated to load malicious scripts. The effectiveness of these campaigns lies in their ability to mimic legitimate software platforms, enhancing their stealth and complicating detection efforts.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (23 / 897 total)
All CIDR URL domain hostname FileHash-SHA256 FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 03ba8a86868939ef0f8eb971eb9287e577998b16 2025-06-11
FileHash-SHA1 265fef2587f49cd180d50c82395626c0b4ca66a1 2025-06-11
FileHash-SHA1 409279d1bf45588e55f78323ba2da767db4101a9 2025-06-11
FileHash-SHA1 ac64a7ac5ad2bfad58cdd43c0ab155e7718417d6 2025-06-11
FileHash-SHA1 bc12e8e0c66e70a379cd9bae8f962ab3e823550c 2025-06-11
FileHash-SHA1 db38be7fddb09ad13b5c2f75f08a9f6dc317c5ae 2025-06-11
FileHash-SHA1 de61c9731d5095cf3cb02d60ec32be895fbe06cc 2025-06-11
FileHash-SHA1 df2cc2b6724bfa135b2cb0228b3fd8ba3d709bec 2025-06-11
FileHash-SHA1 17083d55f17031cd42bfaa14739fce6e7d01af6b 2025-06-11
FileHash-SHA1 1730bfc3702138096288ccfdd58ade88c08b81c7 2025-06-11
FileHash-SHA1 22ea493e4bd681ee2fe61dbca1109f016ee70be1 2025-06-11
FileHash-SHA1 3aaad62f6a2400a6f6eaac7084c0b91cda9148d0 2025-06-11
FileHash-SHA1 4c6141cf30595f760adc634254ce55d394a1a9bd 2025-06-11
FileHash-SHA1 537bbcc411201009aef54ac194b558f2f1eab26d 2025-06-11
FileHash-SHA1 5dd00a4c2f9972e437170f6fda77c913237d8b38 2025-06-11
FileHash-SHA1 713a1df1c217f3cab48e8dee44e51fccd3e3152c 2025-06-11
FileHash-SHA1 8416bd8ee2fbd19919aa673ee6290724a1cb372f 2025-06-11
FileHash-SHA1 8e8c2731570a93466e91c8e8ebf901c9f46fb69b 2025-06-11
FileHash-SHA1 b94b3dc346e8a17d27feedf33bd1a52aadd21fac 2025-06-11
FileHash-SHA1 d40763111d060d63f9adc43ef4b28dfbb1239296 2025-06-11
FileHash-SHA1 d5f852c2fec410e4e23efdfb19c4a90dffc4563a 2025-06-11
FileHash-SHA1 df373e200a31c5d39e6c26c5792ef37a3b125284 2025-06-11
FileHash-SHA1 fb4202f3a0886bd7e2c4c6d69f0c144ea4fb5245 2025-06-11