THE HUNTER’S LEDGER
IOC Feed
FACEIT ClickFix Pages Point CS2 Players to a Script URL That VirusTotal Ties to a Steam-Focused Executable
13 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
13 shown
TypeIndicator
url https://the-hunters-ledger.com/hunting-detections/newdouble-clickfix-detections/
sha256 1366b8ca7f315142ba9989241402758cf2a86e5568a28da0942e1810fe12c324
sha256 dd29536b27649fa897d39198f3ec32d05215b9c6d2864acc32f51de648a25e25
sha1 b7119d01b2e49938ac310543e7240815e26b711c
sha1 f9d075fc57b6b27a6066734a9a9ba25d666ba9db
md5 405186a1740ede3e8c56bbf81c043e7e
md5 6971a368b4164f8d53a9041b717e8ace
md5 87e8479ef75eb55bf7a09ca6b8a60c49
path %APPDATA%\Microsoft\Windows\Libraries\Cache\steamwebhelper.exe
path %APPDATA%\MyApp\y.dat
path %APPDATA%\MyApp\y.ps1
filename x.exe
filename y.ps1

5 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Do not block

These values came out of this investigation, but blocking them would break something legitimate, whether a shared service, a bystander's infrastructure, or the victim's own equipment. They are listed here because they still matter for hunting, and they are deliberately excluded from the copy and download buttons above.

TypeIndicatorWhy it stays off a blocklist
ipv4 202.71.14.31 Host of the first-stage script and the second-stage executable named in the clipboard command
domain newdouble-authentification.com Fake verification lure page
domain newdoubleauthentification.com Fake verification lure page
url http://202.71.14.31/x/x.exe Second-stage executable URL configured inside the script
url http://202.71.14.31/y/ Open directory listing on the payload host; it lists one file, y.ps1
url http://202.71.14.31/y/y.ps1 First-stage script URL placed on the clipboard by the lure page
sha256 f6afe770a78d3655c367819b0c5e8afb623cf56b9922c179efbc89fea1a9ea86 Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose.
sha1 17602aa32d21a7bba16e1c657b4a818463fc560a Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose.
md5 3b5072ed500f8d2a34027ed6ea7f0a30 Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose.
md5 83cb3b733cad23c702777baa42efaca3 Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.