PULSE NAME
Botnet Trojan delivered through ClickFix and EtherHiding
WHITE AlienVault 2026-02-27 Modified: 2026-02-27
25
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses.
Indicators of Compromise (25)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 20b8714b6e0f2459a21b8e315b79d290 2026-02-27
FileHash-MD5 3536f953ee2381215ecc1001653b03c2 2026-02-27
FileHash-MD5 b5ad76ef744401aa648f56a83e0db00c 2026-02-27
FileHash-MD5 e2d8dac1c3fe671f4244198953759827 2026-02-27
FileHash-SHA1 4496afeb004df243b656d620f76ffdceef00b345 2026-02-27
FileHash-SHA1 507e814c39b200b05f596d9569675aeb6c25ab4a 2026-02-27
FileHash-SHA1 96f2c607aec4432ccc7b762f9927c91ee04fb0e3 2026-02-27
FileHash-SHA1 af6bbae2933e65d632f4f4624315c00d205bf6f7 2026-02-27
FileHash-SHA1 c519a422d68e8d93f2b98ecb3fa064398045535e 2026-02-27
FileHash-SHA256 82220e03c9b50959fda633576869c2744c3d45b77b7638b3e975ecaa5d2a6a64 2026-02-27
FileHash-SHA256 a6f7210ecc4769228081f0ea8b74d4d4c2b73baff05ec46e87cba996f04d296b 2026-02-27
FileHash-SHA256 c637ad6ad634f77f83a78302a0bfec8a21afe8f1852b3db262a76202bf118eb1 2026-02-27
FileHash-SHA256 e1016ff75db679ddb522f7e0e5321525f0dc22e2626b193680ce4389fcfb63ae 2026-02-27
URL http://dltruek.com/data 2026-02-27
URL http://dltruek.com/helpU.php 2026-02-27
URL http://dltruek.com/test.php 2026-02-27
domain checkpointviewzen.com 2026-02-27
domain dltruek.com 2026-02-27
domain dltucra.com 2026-02-27
domain ldture.com 2026-02-27
domain ldveriz.com 2026-02-27
domain oklefe.com 2026-02-27
domain opsecdefcloud.com 2026-02-27
domain tesseract-ocr.com 2026-02-27
hostname bsc-testnet.publicnode.com 2026-02-27