{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "ErrTraffic is a high-conversion MaaS framework. Detecting the endpoint results of its ClickFix lures is critical as its network infrastructure rotates frequently via blockchain resolvers."
      },
      "name": "ErrTraffic ClickFix PowerShell and Infostealer Activity",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1059.001",
        "attack.t1555",
        "attack.t1071"
      ],
      "series": {
        "slug": "errtraffic-a-growing-clickfix-malware-distribution-framework",
        "index": 2,
        "title": "ErrTraffic: A Growing ClickFix Malware Distribution Framework",
        "total": 2
      },
      "related": [
        {
          "hunt": "wordpress-backdoor-persistence",
          "reason": "This hunt focuses on the victim endpoints; investigating the server-side WordPress backdoors used to deliver ErrTraffic requires separate analysis of PHP activity.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "errtraffic-infrastructure-delivery",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt correlates evidence across three surfaces\u2014DNS resolution of suspicious domains, rare process access to browser credential stores, and specific PowerShell command-line markers\u2014to identify a complete attack chain that a single rule on any one surface would miss or over-alert on.",
      "coverage": [
        {
          "stage": "powershell-payload-execution",
          "steps": [
            "dns-to-errtraffic-c2",
            "powershell-clickfix-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "infostealer-credential-access",
          "steps": [
            "rare-credential-file-access"
          ],
          "status": "covered"
        },
        {
          "stage": "wordpress-credential-compromise",
          "reason": "Relates to initial compromise of the distribution infrastructure, not the victim endpoint.",
          "status": "out_of_scope"
        },
        {
          "stage": "backdoor-persistence",
          "reason": "WordPress server persistence is handled in a separate hunt.",
          "status": "out_of_scope"
        },
        {
          "stage": "blockchain-c2-resolution",
          "reason": "Monitoring of blockchain smart contracts is out of scope for endpoint telemetry.",
          "status": "out_of_scope"
        },
        {
          "stage": "clickfix-lure-delivery",
          "reason": "Requires web server logs or browser instrumentation not present in the provided surfaces.",
          "status": "out_of_scope"
        },
        {
          "stage": "clipboard-command-injection",
          "reason": "Endpoint surfaces cannot currently see the clipboard manipulation event.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "WordPress Account Compromise",
            "slug": "wordpress-credential-compromise",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "harvested credentials",
              "WordPress sites",
              "Exploit.IN forum"
            ]
          },
          {
            "name": "PHP Backdoor Deployment",
            "slug": "backdoor-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "PHP backdoors",
              "malicious WordPress plugin",
              "ErrTraffic framework injection"
            ]
          },
          {
            "name": "EtherHiding C2 Resolution",
            "slug": "blockchain-c2-resolution",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "Polygon blockchain",
              "0x08207B087F61d7e95E441E15fd6d40BEfd6eD308",
              "Quicknode RPC",
              "llc-image-ico.click",
              ".beer",
              ".cfd",
              ".club",
              ".click",
              ".cyou",
              ".lat",
              ".sbs",
              ".shop",
              ".xyz"
            ]
          },
          {
            "name": "Social Engineering Lure Delivery",
            "slug": "clickfix-lure-delivery",
            "tactic": "execution",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "/cf.js",
              "/api/css.js",
              "/api/index.php",
              "BSOD lure",
              "reCAPTCHA lure",
              "Cloudflare Turnstile lure"
            ]
          },
          {
            "name": "Malicious Clipboard Injection",
            "slug": "clipboard-command-injection",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "PowerShell command copied to clipboard"
            ]
          },
          {
            "name": "User-Executed PowerShell Payload",
            "slug": "powershell-payload-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "powershell.exe",
              "Net.WebClient download",
              "mode=download"
            ]
          },
          {
            "name": "Infostealer Data Theft",
            "slug": "infostealer-credential-access",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Vidar",
              "Stealc",
              "Remus",
              "Salat"
            ]
          }
        ],
        "summary": "ErrTraffic is a Malware-as-a-Service (MaaS) framework that compromises WordPress sites to distribute infostealers using the 'ClickFix' social engineering technique. It uses the EtherHiding technique to resolve its command-and-control infrastructure via blockchain smart contracts and delivers malicious PowerShell commands that victims are tricked into executing manually."
      },
      "severity": "high",
      "rationale": "Begin with Windows workstations and specifically examine DNS resolution of blockchain-derived domains. Use the results of the DNS query to narrow the scope for subsequent process and file queries.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "sekoia-errtraffic",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[domain]",
          "default": [
            "llc-image-ico.click",
            "llc-image-ico.beer",
            "exploit.in"
          ],
          "description": "ErrTraffic C2 domains and related infrastructure observed in campaigns."
        },
        "scope_hosts": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames from the scoping step to narrow the search."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "legitimate_browsers": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            "chrome.exe",
            "msedge.exe",
            "firefox.exe",
            "brave.exe"
          ],
          "description": "Known browser processes allowed to access credential stores."
        },
        "powershell_binaries": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            "powershell.exe",
            "pwsh.exe"
          ],
          "description": "PowerShell executable names to monitor."
        },
        "credential_file_names": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            "login data",
            "web data",
            "cookies"
          ],
          "description": "Targeted browser credential files (case-insensitive match)."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework",
          "name": "Sekoia \u2014 Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-endpoint-telemetry",
          "risk": "A host without an agent will return zero rows, leading to a false sense of security regarding the total infection rate.",
          "question": "whether an infection occurred on a host that does not report process or file activity",
          "requires": "EDR agent coverage on all assets"
        },
        {
          "id": "clipboard-visibility",
          "risk": "The hunt relies on seeing the execution after the user pastes the command; the injection of the command itself into the clipboard is not visible on the provided surfaces.",
          "stage": "powershell-payload-execution",
          "question": "the exact contents of the clipboard lure before execution",
          "requires": "clipboard monitoring surface"
        }
      ]
    },
    "name": "ErrTraffic ClickFix PowerShell and Infostealer Activity",
    "description": "This hunt identifies the endpoint manifestations of the ErrTraffic framework, a Malware-as-a-Service (MaaS) system that uses ClickFix social engineering. It targets the execution of PowerShell commands containing specific download parameters, correlates this with unauthorized access to browser credential stores by non-browser processes, and identifies DNS activity targeting blockchain-resolved C2 infrastructure."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "errtraffic-a-growing-clickfix-malware-distribution-framework",
          "index": 2,
          "title": "ErrTraffic: A Growing ClickFix Malware Distribution Framework",
          "total": 2
        },
        "coverage": [
          {
            "stage": "powershell-payload-execution",
            "steps": [
              "dns-to-errtraffic-c2",
              "powershell-clickfix-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "infostealer-credential-access",
            "steps": [
              "rare-credential-file-access"
            ],
            "status": "covered"
          },
          {
            "stage": "wordpress-credential-compromise",
            "reason": "Relates to initial compromise of the distribution infrastructure, not the victim endpoint.",
            "status": "out_of_scope"
          },
          {
            "stage": "backdoor-persistence",
            "reason": "WordPress server persistence is handled in a separate hunt.",
            "status": "out_of_scope"
          },
          {
            "stage": "blockchain-c2-resolution",
            "reason": "Monitoring of blockchain smart contracts is out of scope for endpoint telemetry.",
            "status": "out_of_scope"
          },
          {
            "stage": "clickfix-lure-delivery",
            "reason": "Requires web server logs or browser instrumentation not present in the provided surfaces.",
            "status": "out_of_scope"
          },
          {
            "stage": "clipboard-command-injection",
            "reason": "Endpoint surfaces cannot currently see the clipboard manipulation event.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.",
        "blind_spots": [
          {
            "id": "missing-endpoint-telemetry",
            "risk": "A host without an agent will return zero rows, leading to a false sense of security regarding the total infection rate.",
            "question": "whether an infection occurred on a host that does not report process or file activity",
            "requires": "EDR agent coverage on all assets"
          },
          {
            "id": "clipboard-visibility",
            "risk": "The hunt relies on seeing the execution after the user pastes the command; the injection of the command itself into the clipboard is not visible on the provided surfaces.",
            "stage": "powershell-payload-execution",
            "question": "the exact contents of the clipboard lure before execution",
            "requires": "clipboard monitoring surface"
          }
        ],
        "scoping_notes": "Begin with Windows workstations and specifically examine DNS resolution of blockchain-derived domains. Use the results of the DNS query to narrow the scope for subsequent process and file queries.",
        "beyond_detection": "This hunt correlates evidence across three surfaces\u2014DNS resolution of suspicious domains, rare process access to browser credential stores, and specific PowerShell command-line markers\u2014to identify a complete attack chain that a single rule on any one surface would miss or over-alert on."
      }
    },
    {
      "id": "dns-to-errtraffic-c2",
      "type": "query",
      "label": "DNS lookups to ErrTraffic C2",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify hosts resolving domains associated with the ErrTraffic framework to narrow the estate for behavioural queries.",
        "expected_signal": "Hosts resolving known C2 domains. Silence indicates no direct resolution of the provided domains, which may occur if the attacker rotates blockchain-derived infrastructure."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "DNS lookups to ErrTraffic C2",
        "reads": [
          "device_hostname",
          "query_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts resolving known C2 domains. Silence indicates no direct resolution of the provided domains, which may occur if the attacker rotates blockchain-derived infrastructure.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "powershell-clickfix-execution",
      "type": "query",
      "label": "PowerShell execution with ClickFix lures",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find PowerShell commands containing the specific download parameters and lure markers described in the report.",
        "expected_signal": "Process rows showing PowerShell used with ClickFix download markers. Silence means no such commands were executed within the window."
      },
      "parents": [
        {
          "id": "dns-to-errtraffic-c2"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "PowerShell execution with ClickFix lures",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Process rows showing PowerShell used with ClickFix download markers. Silence means no such commands were executed within the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-credential-file-access",
      "type": "query",
      "label": "Rare process access to browser data",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50",
        "surface": "hb_file_activity",
        "description": "Identify non-browser processes reading sensitive browser credential files to establish harvesting behaviour.",
        "expected_signal": "A process that is not a browser reading browser databases. Silence suggests no suspicious harvesting occurred on those hosts."
      },
      "parents": [
        {
          "id": "dns-to-errtraffic-c2"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare process access to browser data",
        "reads": [
          "device_hostname",
          "process_name",
          "file_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A process that is not a browser reading browser databases. Silence suggests no suspicious harvesting occurred on those hosts.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-infection",
      "type": "analytic",
      "label": "Triage ErrTraffic infection",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "dns-to-errtraffic-c2",
          "powershell-clickfix-execution",
          "rare-credential-file-access"
        ],
        "objective": "Determine if a host was compromised by an ErrTraffic lure and if credential harvesting occurred.",
        "description": "Correlate the DNS resolution of C2 domains, the execution of lure-specific PowerShell commands, and the harvesting of browser data.",
        "max_iterations": 4,
        "expected_signal": "A verdict of malicious, suspicious, or benign per host based on the evidence chain.",
        "success_criteria": "A per-host verdict that identifies the malicious binary responsible for file access and its origin via PowerShell."
      },
      "parents": [
        {
          "id": "powershell-clickfix-execution",
          "kind": "merge"
        },
        {
          "id": "rare-credential-file-access",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-infection verdict is malicious for at least one host",
        "condition": "the triage-infection verdict is malicious for at least one host",
        "blind_spot": "missing-endpoint-telemetry",
        "confidence": "high",
        "description": "Route the workflow based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-infection"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain the infostealer infection immediately to prevent further exfiltration.",
        "instructions": "Isolate the endpoint from the network and revoke any active cloud sessions for the affected user.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent findings and identify the specific malware variant and C2 infrastructure.",
        "instructions": "Review the cited rows from the triage step. Verify the binary that accessed the credential stores. Search for other persistence mechanisms installed by the payload."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt closure",
      "config": {
        "assignee": "analyst",
        "description": "Document the outcome and refine future hunt parameters.",
        "instructions": "Record the results of the hunt. If new C2 domains were identified during forensic review, update the c2_domains parameter for future runs."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}