{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "iClickFix is a widespread malware framework that has compromised thousands of sites to deliver NetSupport RAT; a negative result over the estate confirms the current social engineering campaign has not successfully landed a beachhead."
      },
      "name": "iClickFix: NetSupport RAT Execution and Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1059.001",
        "attack.t1566",
        "attack.t1547.001",
        "attack.t1041",
        "attack.t1090.003",
        "attack.t1021.001"
      ],
      "series": {
        "slug": "iclickfix-wordpress-targeting-framework-using-clickfix",
        "index": 2,
        "title": "iClickFix: WordPress-targeting framework using ClickFix",
        "total": 2
      },
      "related": [
        {
          "hunt": "iclickfix-wordpress-injection-discovery",
          "reason": "Tracking the compromised WordPress sites and the TDS redirection belongs to an external-scanning or network-centric hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "iclickfix-web-redirection-delivery",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule might catch the specific scottvmorton domain, but this hunt correlates the initial PowerShell execution with rare ProgramData persistence and gateway connections, allowing an analyst to see the full intrusion chain rather than a single disjointed alert.",
      "coverage": [
        {
          "stage": "powershell-payload-execution",
          "steps": [
            "lead-powershell-downloader"
          ],
          "status": "covered"
        },
        {
          "stage": "rat-persistence-and-dropper-cleanup",
          "steps": [
            "rare-programdata-binaries"
          ],
          "status": "covered"
        },
        {
          "stage": "netsupport-rat-c2-and-data-theft",
          "steps": [
            "c2-dns-lookups"
          ],
          "status": "covered"
        },
        {
          "stage": "compromised-wordpress-injection",
          "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "tds-redirection-and-payload-delivery",
          "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "clickfix-clipboard-social-engineering",
          "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Malicious JavaScript Injection",
            "slug": "compromised-wordpress-injection",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "ic-tracker-js",
              "ksfldfklskdmbxcvb.com",
              "ahpc.gov.gh",
              "dns-prefetch"
            ]
          },
          {
            "name": "TDS Redirection and Script Fetching",
            "slug": "tds-redirection-and-payload-delivery",
            "tactic": "execution",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "ototaikfffkf.com/fffa.js",
              "ksdkgsdkgkgmgm.pro/ofofo.js",
              "booksbypatriciaschultz.com/liner.php",
              "x-robots-tag: noindex",
              "YOURLS admin panel"
            ]
          },
          {
            "name": "ClickFix Clipboard Social Engineering",
            "slug": "clickfix-clipboard-social-engineering",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "navigator.clipboard.writeText",
              "Verify you are human",
              "Ctrl + V",
              "Win + R",
              "Unusual Web Traffic Detected"
            ]
          },
          {
            "name": "Malicious PowerShell Downloader",
            "slug": "powershell-payload-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "powershell -w hidden -nop -c",
              "scottvmorton.com/tytuy.json",
              "05b03a25e10535c5c8e2327ee800ff5894f5dbfaf72e3fdcd9901def6f072c6d",
              "8db6.ps1"
            ]
          },
          {
            "name": "NetSupport RAT Persistence and Evasion",
            "slug": "rat-persistence-and-dropper-cleanup",
            "tactic": "persistence",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "ProgramData\\S1kCMNfZi3\\",
              "client32.exe",
              "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
              "SecureModule Engine v1.0.0",
              "RunMRU"
            ]
          },
          {
            "name": "Command and Control and Data Theft",
            "slug": "netsupport-rat-c2-and-data-theft",
            "tactic": "command-and-control",
            "techniques": [
              "T1041",
              "T1090.003",
              "T1021.001",
              "T1555"
            ],
            "observables": [
              "pusykakimao.com:443",
              "fnotusykakimao.com:443",
              "/fakeurl.htm",
              "client32.ini",
              "licensee KAKAN"
            ]
          }
        ],
        "summary": "IClickFix is a WordPress-targeting framework that compromises legitimate sites to inject malicious JavaScript and redirect users through a YOURLS-based Traffic Distribution System. Victims are tricked by a ClickFix-style fake CAPTCHA lure into executing a PowerShell command that downloads and deploys the NetSupport RAT for persistent remote access and data exfiltration."
      },
      "severity": "high",
      "rationale": "Focus on Windows endpoints with direct internet access and active human users, as the ClickFix lure requires interaction through a browser.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "https://blog.sekoia.io/meet-iclickfix-a-widespread-wordpress-targeting-framework-using-the-clickfix-tactic/",
            "kind": "article",
            "observed": "2025-12-09"
          },
          "type": "list[domain]",
          "default": [
            "pusykakimao.com",
            "fnotusykakimao.com",
            "scottvmorton.com"
          ],
          "description": "C2 domains identified in the iClickFix research; these are used for payload delivery and NetSupport gateway communication."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.sekoia.io/meet-iclickfix-a-widespread-wordpress-targeting-framework-using-the-clickfix-tactic/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.sekoia.io/meet-iclickfix-a-widespread-wordpress-targeting-framework-using-the-clickfix-tactic/",
          "name": "Sekoia \u2014 IClickFix: WordPress-targeting framework using ClickFix"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-process-telemetry",
          "risk": "The hunt relies on the first command-line downloader; if the attacker changes the delivery command but keeps the script behavior, the lead query will fail to fire.",
          "stage": "powershell-payload-execution",
          "question": "What specifically did the obfuscated PowerShell script do after downloading the payload?",
          "requires": "hb_script_activity for script block logging"
        },
        {
          "id": "no-network-telemetry",
          "risk": "DNS lookups confirm the host talked to the C2, but cannot confirm if data exfiltration occurred without HTTP URI visibility.",
          "stage": "netsupport-rat-c2-and-data-theft",
          "question": "Was data exfiltrated to /fakeurl.htm?",
          "requires": "hb_http_activity with URI inspection"
        }
      ]
    },
    "name": "iClickFix: NetSupport RAT Execution and Persistence",
    "description": "The adversary uses compromised WordPress sites to deliver a fake CAPTCHA that tricks users into executing malicious PowerShell. This hunt identifies the initial hidden PowerShell downloader pattern. If the hunt finds suspicious execution, it fans out to look for rare NetSupport binaries in ProgramData and network traffic to the infrastructure named in recent research. An agent weighs the execution and post-exploitation evidence to identify compromised hosts for isolation."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "iclickfix-wordpress-targeting-framework-using-clickfix",
          "index": 2,
          "title": "iClickFix: WordPress-targeting framework using ClickFix",
          "total": 2
        },
        "coverage": [
          {
            "stage": "powershell-payload-execution",
            "steps": [
              "lead-powershell-downloader"
            ],
            "status": "covered"
          },
          {
            "stage": "rat-persistence-and-dropper-cleanup",
            "steps": [
              "rare-programdata-binaries"
            ],
            "status": "covered"
          },
          {
            "stage": "netsupport-rat-c2-and-data-theft",
            "steps": [
              "c2-dns-lookups"
            ],
            "status": "covered"
          },
          {
            "stage": "compromised-wordpress-injection",
            "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "tds-redirection-and-payload-delivery",
            "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "clickfix-clipboard-social-engineering",
            "reason": "Belongs to another part of the 'iClickFix: WordPress-targeting framework using ClickFix' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.",
        "blind_spots": [
          {
            "id": "limited-process-telemetry",
            "risk": "The hunt relies on the first command-line downloader; if the attacker changes the delivery command but keeps the script behavior, the lead query will fail to fire.",
            "stage": "powershell-payload-execution",
            "question": "What specifically did the obfuscated PowerShell script do after downloading the payload?",
            "requires": "hb_script_activity for script block logging"
          },
          {
            "id": "no-network-telemetry",
            "risk": "DNS lookups confirm the host talked to the C2, but cannot confirm if data exfiltration occurred without HTTP URI visibility.",
            "stage": "netsupport-rat-c2-and-data-theft",
            "question": "Was data exfiltrated to /fakeurl.htm?",
            "requires": "hb_http_activity with URI inspection"
          }
        ],
        "scoping_notes": "Focus on Windows endpoints with direct internet access and active human users, as the ClickFix lure requires interaction through a browser.",
        "beyond_detection": "A simple detection rule might catch the specific scottvmorton domain, but this hunt correlates the initial PowerShell execution with rare ProgramData persistence and gateway connections, allowing an analyst to see the full intrusion chain rather than a single disjointed alert."
      }
    },
    {
      "id": "lead-powershell-downloader",
      "type": "query",
      "label": "PowerShell Hidden Downloader",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' AND LOWER(process_cmd_line) LIKE '%-w hidden%' AND (LOWER(process_cmd_line) LIKE '%iwr%' OR LOWER(process_cmd_line) LIKE '%invoke-webrequest%' OR LOWER(process_cmd_line) LIKE '%scottvmorton.com%')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify the initial ClickFix-delivered command that uses hidden PowerShell windows to download the second-stage payload.",
        "expected_signal": "Rows show PowerShell executing with hidden windows and downloader cmdlets targeting the delivery domain scottvmorton.com. Silence means no overt ClickFix execution was detected."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "PowerShell Hidden Downloader",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' AND LOWER(process_cmd_line) LIKE '%-w hidden%' AND (LOWER(process_cmd_line) LIKE '%iwr%' OR LOWER(process_cmd_line) LIKE '%invoke-webrequest%' OR LOWER(process_cmd_line) LIKE '%scottvmorton.com%')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows show PowerShell executing with hidden windows and downloader cmdlets targeting the delivery domain scottvmorton.com. Silence means no overt ClickFix execution was detected.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "agent-lead-read",
      "type": "analytic",
      "label": "Initial Lead Assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "lead-powershell-downloader"
        ],
        "objective": "Determine if the PowerShell command found in the lead matches the iClickFix pattern: hidden window, execution policy bypass, and use of iwr or invoke-webrequest to the scottvmorton delivery domain.",
        "description": "Evaluate whether the identified PowerShell commands match the obfuscated ClickFix delivery pattern.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether the command-line arguments indicate a malicious downloader.",
        "success_criteria": "A verdict of malicious or suspicious for the lead command."
      },
      "parents": [
        {
          "id": "lead-powershell-downloader"
        }
      ]
    },
    {
      "id": "gate-decision",
      "type": "checkpoint",
      "label": "Gate: Proceed to Enrichment?",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-lead-read verdict is malicious or suspicious for at least one host",
        "condition": "the agent-lead-read verdict is malicious or suspicious for at least one host",
        "blind_spot": "limited-process-telemetry",
        "confidence": "high",
        "description": "Stop the hunt if the lead activity is determined to be benign or non-existent to save resources.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-lead-read"
        }
      ]
    },
    {
      "id": "rare-programdata-binaries",
      "type": "query",
      "label": "Rare ProgramData Process Paths",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, LOWER(process_path) AS path, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\programdata\\%' AND (LOWER(process_path) LIKE '%client32.exe' OR LOWER(process_path) LIKE '%\\s1kcmnfzi3\\%')) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, path",
        "surface": "hb_process_activity",
        "description": "Identify NetSupport RAT binaries like client32.exe in unique, non-standard ProgramData subdirectories per host.",
        "expected_signal": "A binary path seen on only a few hosts across the fleet; legitimate ProgramData software is typically widespread."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare ProgramData Process Paths",
        "reads": [
          "device_hostname",
          "process_path",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, LOWER(process_path) AS path, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\programdata\\%' AND (LOWER(process_path) LIKE '%client32.exe' OR LOWER(process_path) LIKE '%\\s1kcmnfzi3\\%')) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, path",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A binary path seen on only a few hosts across the fleet; legitimate ProgramData software is typically widespread.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "path"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "c2-dns-lookups",
      "type": "query",
      "label": "DNS Lookups to NetSupport C2",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Find connections to the specific domains used by the NetSupport RAT gateways as identified in the research.",
        "expected_signal": "DNS resolutions for pusykakimao.com or fnotusykakimao.com associated with processes like explorer.exe or client32.exe."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS Lookups to NetSupport C2",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "DNS resolutions for pusykakimao.com or fnotusykakimao.com associated with processes like explorer.exe or client32.exe.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "agent-final-triage",
      "type": "analytic",
      "label": "Consolidate Infection Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "agent-lead-read",
          "rare-programdata-binaries",
          "c2-dns-lookups"
        ],
        "objective": "Determine if the host is compromised by NetSupport RAT by weighing the lead execution, the presence of rare ProgramData binaries, and network traffic to known gateway domains.",
        "description": "Correlate the PowerShell lead with the rare ProgramData binaries and C2 connections per host.",
        "max_iterations": 5,
        "expected_signal": "A finalized list of hosts showing the full attack chain from delivery to C2 contact.",
        "success_criteria": "A verdict of malicious per host citing the PowerShell process, the local file path, and the DNS lookup."
      },
      "parents": [
        {
          "id": "rare-programdata-binaries",
          "kind": "merge"
        },
        {
          "id": "c2-dns-lookups",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-route-response",
      "type": "checkpoint",
      "label": "Route on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-final-triage verdict is malicious for at least one host",
        "condition": "the agent-final-triage verdict is malicious for at least one host",
        "blind_spot": "no-network-telemetry",
        "confidence": "high",
        "description": "Direct the hunt towards immediate containment for confirmed malicious results.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-final-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Endpoint",
      "config": {
        "target": "endpoint",
        "description": "Prevent further exfiltration and stop the adversary from using the RAT access.",
        "instructions": "Isolate the host, preserve the ProgramData subdirectories for forensics, and identify the user credentials that were active at the time of the PowerShell execution.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-route-response",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Triage Review",
      "config": {
        "assignee": "analyst",
        "description": "Perform manual confirmation of the RAT infection and tune detection logic.",
        "instructions": "Review the cited rows from the triage step. Verify the ProgramData path and the DNS connection process. If confirmed, check for lateral movement attempts via RDP and check the clipboard content if possible."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "default"
        },
        {
          "id": "gate-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "decision-route-response",
          "branch": "default"
        },
        {
          "id": "decision-route-response",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record negative results for future baseline comparison.",
        "instructions": "Record the hunt results. If no malicious activity was found, note any false positives from common PowerShell updaters for future exclusion."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_refutes"
        },
        {
          "id": "decision-route-response",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}