The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves
ActiveSOC found fake-CAPTCHA malware lures rotating domains while Seychelles hosting infrastructure stayed put.
Over five months ActiveSOC tracked four attack chains that began on the same Seychelles-registered hosting network, AS202412, while lure domains, downloads, and command servers changed. Most victims reached fake CAPTCHA pages through ads, and one arrived via an emailed link; the pages copied a command for the Windows Run dialog. Reviewing about 150 alerts, analysts found four cases reached command execution, including a reboot-persistent stealer and a Node.js implant active for nearly two days. One implant retrieved its command server through a blockchain lookup rather than a conventional domain.
- Shared lure hosting was Seychelles-registered AS202412 across multiple ranges.
- Fake CAPTCHA pages pushed clipboard commands into the Windows Run box.
- Four cases reached execution, including a stealer and a Node.js implant.
- One implant resolved its command server through a blockchain lookup.
- Blocking individual domains misses infrastructure that keeps adding space.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ai-nexora.sbs | nd in public scans, not observed on monitored hosts. Domain ai-nexora[.]sbs Additional name found in public scans, not observed on mo |
| domain | alianzeg.shop | . Domain newtdsone[.]shop Traffic-distribution name. Domain alianzeg[.]shop Traffic-distribution name. Domain getfix[.]win Historical |
| domain | amazonaws.com | d. Domain 2d4e5f6-7a8b-4c2d-9e1f-3b5a7c8d9e0fc.s3.us-east-1.amazonaws[.]com First-stage batch-script host as transcribed in the sourc |
| domain | approvalrequest-api.com | ipt host in one setting and stager front in another. Domain approvalrequest-api[.]com Installer source in a pasted command. Domain 2d4e5f6-7a8b |
| domain | auth-code-check.info | me not observed resolving in monitored environments. Domain auth-code-check[.]info Related name not observed resolving in monitored environm |
| domain | auth-id-browser.info | ounced during observation; verify current ownership. Domain auth-id-browser[.]info Lure domain observed resolving to the shared host. Domain |
Full article1,819 words · extracted from cybersecuritynews.com · click to collapse
Fake verification pages are steering people toward malware, but the web addresses behind the lures keep changing.
Over five months, investigators tracked four different attack chains that began with the same hosting network, even as domains, downloads and command servers shifted. The pattern makes blocking individual websites a poor way to stop the first step.
Most victims reached a fake CAPTCHA through online ads, although one arrived through an emailed link. The page quietly copied a command to the clipboard, then told the visitor to open the Windows Run box and paste it.
As with earlier fake CAPTCHA attacks, following those instructions could start an infection without opening a suspicious attachment.
Analysts from ActiveSOC identified the shared infrastructure while reviewing roughly 150 alerts across monitored environments.
ActiveSOC said in a report shared with Cyber Security News (CSN) that four cases reached command execution, while most contacts stopped at the lure page.
The findings describe a recurring entry point, not evidence that every visitor was infected, and this depicts that the consequences varied widely.
One chain installed a stealer that survived a reboot, while another placed a Node.js implant on a host and remained active for nearly two days.
A separate attempt contacted a cloud storage bucket but showed no confirmed second-stage installation, underscoring the gap between exposure and compromise.
The Domains Keep Disappearing
The common link was a hosting provider’s network registered in the Seychelles. Researchers saw at least seven entry addresses across six separate network ranges, and the provider expanded its announced space during the investigation.
Operators may have used the same service, but the evidence does not establish who controlled the campaigns. On one address alone, the researchers observed 12 lure domains in their telemetry and found 11 more in public scanning data.
.webp)
Others used compromised retail or restaurant sites, echoing research on poisoned redirects, where the browser’s address bar showed a genuine website while an injected script supplied the fake challenge. That weakness makes simple domain checks unreliable.
This investigation highlights what stays put behind changing names and why removing one lure at a time changes little. Some pages even copied their host site’s name into the challenge, making the prompt appear to belong there.
One captured template mixed Windows instructions with a misspelled reference to a Mac feature. Once people pasted the command, the next step could come from the provider itself, a cloud bucket or an installer disguised as software.
installer placed a malicious library beside a legitimate application, a technique resembling software installer sideloading cases reported elsewhere. Those examples are context, not evidence that the separate campaigns share an operator.activesoc.blackhillsinfosec+1
Blocking the First Step
Speed mattered in one documented case: the browser reached the lure, and the user ran the pasted command 41 seconds later. An endpoint alert followed one second after execution.
Researchers could not tell whether protection stopped the next stage or the cloud bucket simply failed to deliver it, so they did not call that host compromised.
Other chains were harder to follow after the initial page. One implant retrieved its command server through a blockchain lookup rather than a conventional domain, an approach explained in blockchain based command control reporting.
.webp)
This is why stopping the lure does not replace monitoring for activity already running on a device. ActiveSOC recommends checking an organization’s own outbound traffic before blocking the provider’s network, because another environment could rely on an address there.
Then block the network’s announced ranges, keep logs of denied connections and refresh the range list. A fixed list can miss newly added space or block addresses that have changed hands.
Defenders should also watch for browsers handing off to command interpreters, unsigned libraries beside signed software, and trusted runtimes launched from user writable folders.
Suspicious ads deserve attention, but an alert on a page visit alone does not prove malware ran. Teach users that a website asking them to paste a clipboard command into the Run box is not performing a verification.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| ASN | AS202412 | Shared entry-point hosting network. Check local traffic and current announcements before blocking.activesoc.blackhillsinfosec |
| IP address | 178.16.52[.]101 | Lure host linked to observed and publicly scanned domains. |
| IP address | 178.16.53[.]137 | Injected-script and advertising redirect host. |
| IP address | 158.94.211[.]92 | In-memory payload staging host. |
| IP address | 158.94.208[.]213 | Lure host in the 41-second case. |
| IP address | 158.94.208[.]104 | Browser contact. |
| IP address | 91.92.243[.]161 | Browser contact; no lure domain recovered. |
| IP address | 178.16.54[.]253 | Lure host; also hosted an unrelated site. |
| IP address | 178.16.54[.]40 | Outbound contact. |
| IP address | 178.16.55[.]232 | Outbound contact. |
| IP address | 91.92.241[.]111 | Outbound contact. |
| IP address | 158.94.211[.]76 | Outbound contact. |
| IP address | 130.12.180[.]63 | Lure host reached through an emailed short link. |
| IP address | 130.12.180[.]174 | Outbound contact. |
| IP address | 91.92.240[.]127 | Script source recovered in a sandbox, not observed on a monitored host. |
| IP address | 16.15.228[.]38 | Cloud storage endpoint used in the timeline; not attacker-owned and should not be blocked solely on this basis. |
| IP address | 193.202.84[.]17 | Primary command server and data sink. |
| IP address | 176.65.144[.]127 | Blockchain-resolved command server observed on TCP port 3847; assess all ports. |
| Network range | 91.92.240[.]0/24 | Provider range containing the sandbox-observed script source. |
| Network range | 130.12.180[.]0/24 | Range blocked during the emailed-link response; verify current ownership. |
| Network range | 172.111.246[.]0/24 | Additional range the provider announced during observation; verify current ownership. |
| Domain | auth-id-browser[.]info | Lure domain observed resolving to the shared host. |
| Domain | enter-code-cdn[.]info | Lure domain observed resolving to the shared host. |
| Domain | authorization-cdn-press-enter[.]info | Lure domain observed resolving to the shared host. |
| Domain | enter-press-cdn[.]info | Lure domain observed resolving to the shared host. |
| Domain | authorization-code[.]info | Lure domain observed resolving to the shared host. |
| Domain | enter-pverif-code[.]info | Lure domain observed resolving to the shared host. |
| Domain | clacndjsvulnarbi[.]beer | Lure domain observed resolving to the shared host. |
| Domain | fingerprint-verification[.]info | Lure domain observed resolving to the shared host. |
| Domain | clnsdns[.]beer | Lure domain observed resolving to the shared host. |
| Domain | framework-css-styles-js[.]beer | Lure domain observed resolving to the shared host. |
| Domain | codeverificatrorcl[.]info | Lure domain observed resolving to the shared host; also seen prepared in advance. |
| Domain | idverification-code[.]beer | Lure domain observed resolving to the shared host. |
| Domain | fraudtechnology[.]com | Related name not observed resolving in monitored environments. |
| Domain | auth-code-check[.]info | Related name not observed resolving in monitored environments. |
| Domain | id-verif-code[.]info | Related name not observed resolving in monitored environments. |
| Domain | enter-press-code[.]info | Related name not observed resolving in monitored environments. |
| Domain | authorization-press-enter[.]info | Related name not observed resolving in monitored environments. |
| Domain | capcha-cdn-js[.]beer | Related name not observed resolving in monitored environments. |
| Domain | fingerprint-veri[.]info | Additional name found in public scans, not observed on monitored hosts. |
| Domain | verico-de-id[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | bootstrap-maxcdn[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | trunnsns[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | ai-nexora[.]sbs | Additional name found in public scans, not observed on monitored hosts. |
| Domain | chekbrow[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | cdn-plugin-js[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | lcates-vs[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | bnsclod[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | biyaconserver[.]beer | Additional name found in public scans, not observed on monitored hosts. |
| Domain | cdn-2faclov[.]sbs | Additional name found in public scans, not observed on monitored hosts. |
| Domain | catholicsma[.]com | Lure serving a padded Run-box command. |
| Domain | rsvpopenh[.]one | Lure reached through an emailed short link. |
| Domain | marketing080company[.]one | Lure resolving to the provider’s network. |
| Domain | thegreenfortune[.]com | Lure domain. |
| Domain | mnoskemp[.]beer | Archive utility and payload archive host. |
| Domain | pilotkadomen[.]club | Recovered second-stage download destination; execution was not observed. |
| Domain | claritydelivr[.]com | Newly registered staging-related parent domain. |
| Domain | cdn.claritydelivr[.]com | Script host in one setting and stager front in another. |
| Domain | approvalrequest-api[.]com | Installer source in a pasted command. |
| Domain | 2d4e5f6-7a8b-4c2d-9e1f-3b5a7c8d9e0fc.s3.us-east-1.amazonaws[.]com | First-stage batch-script host as transcribed in the source; confirm its unusual label before pivoting. |
| Domain | lockpopclickgetfile[.]monster | Payload-delivery domain. |
| Domain | pipeplane[.]cfd | Delivery host. |
| Domain | pcapps[.]my | Delivery domain using random subdomains. |
| Domain | gettrack[.]my | Delivery domain using random subdomains. |
| Domain | securecab[.]fit | Delivery domain using random subdomains. |
| Domain | uruvita[.]com | Delivery domain. |
| Domain | unhosting[.]site | Delivery domain associated with a 32-hex-character subdomain pattern. |
| Domain | dntds[.]shop | Traffic-distribution name. |
| Domain | nttdss[.]shop | Traffic-distribution name. |
| Domain | sdntds[.]shop | Traffic-distribution name. |
| Domain | ntdnewtds[.]shop | Traffic-distribution name also present in script failover. |
| Domain | dnsnewtds[.]shop | Traffic-distribution name also present in script failover. |
| Domain | newtdsone[.]shop | Traffic-distribution name. |
| Domain | alianzeg[.]shop | Traffic-distribution name. |
| Domain | getfix[.]win | Historical TLS certificate subject. |
| Domain | carrotbunnies[.]com | Stealer command domain resolving to the listed data-sink address. |
| Domain | kerosand[.]net | Blockchain-resolved command domain. |
| Domain | shorturl[.]at | Legitimate shortening service used as an emailed-link wrapper; not an attacker-owned domain. |
| URL path | /jsrepo | Injected-script endpoint on the redirect host. |
| URL path | /teamrepo | Injected-script endpoint on the redirect host. |
| URL pattern | http://approvalrequest-api[.]com\caph.php?token=<redacted> | Installer URL as shown in the source command, including its unusual backslash and redacted token. |
| SHA-256 | 9a736f4812b485f9cf5b1332a791b205b5135a4b3a0c41f473ad9cc9fbe2d75c | MSI dropper. |
| SHA-256 | b004acacd8ef5d7e8a2fd99a7931af0ced87b280d5acd2fde499da4a8f24e916 | Trojanized obs.dll. |
| SHA-256 | 81ecbf004dc9dbf8ea4c50bde1ed55806fb5fdf689d165856112ea9f4d5021e0 | WSql-2.dll. |
| SHA-256 | a410c89db9140ed9dff55bff00b0338fbdffcc709490782c7b28e8a10c11eb3b | cred64.dll plugin; cited from upstream intelligence rather than a chain ActiveSOC investigated. |
| SHA-256 | d77bc0bb3018b6cc834c1af1eefaa1c0b906314308d6ab88588f8d41eb62090c | cmd.cmd loader; cited from upstream intelligence rather than a chain ActiveSOC investigated. |
| MSI product code | {C5907138-B44F-408E-A9CA-4D49FDEBD5AC} | Installer product code that remained stable when filenames changed. |
| File path | %LOCALAPPDATA%\Programs\OBS Studio Enhanced Controller\ | Trojanized install directory. |
| File path | %LOCALAPPDATA%\HostShared\node.exe | Implant runtime location; assess with its script and launch context. |
| File path | app\src\index.js | Script executed by the implant runtime. |
| File path | %LOCALAPPDATA%\Microsoft\ | Embedded Python runtime and extraction-tool drop location. |
| File path | %LOCALAPPDATA%\Temp\ | Randomly named archive staging directory. |
| Registry path | HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ | Persistence location used with a StubPath entry. |
| Process pattern | conhost.exe --headless cmd /c, parented by Explorer.EXE | Observed pasted-command execution pattern; not suspicious without context. |
| File name | obs.dll | Trojanized library loaded by a legitimate application. |
| File name | obs64.exe | Legitimate signed executable used to load the malicious library; not malicious alone. |
| File name | WSql-2.dll | Nonstandard bundled library; not seen loading in the observed host window. |
| File name | tessnet2.dll | Metadata name forged inside WSql-2.dll. |
| File name | RegisterIdr.dll | Nonstandard library seen in sandbox behavior, not on the monitored host. |
| File name | 7za.exe | Standalone extraction utility renamed during delivery; not malicious alone. |
| File name | ._agent.vbs | Hidden script dropped beside the implant runtime. |
| File name | config.cmd | First-stage cloud-hosted batch script. |
| File name | config.py | Later-stage script fetched from the same bucket. |
| File name | node.exe | Signed runtime used by the implant; filename alone is not an indicator. |
| Archive password | popsa | Password for the delivered archive. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.