IOC Feed
FACEIT ClickFix Pages Point CS2 Players to a Script URL That VirusTotal Ties to a Steam-Focused Executable
13 indicators extracted from this
investigation's feed. Filter by type, then copy or download exactly what is on screen.
13 shown
| Type | Indicator |
|---|---|
| url | https://the-hunters-ledger.com/hunting-detections/newdouble-clickfix-detections/ |
| sha256 | 1366b8ca7f315142ba9989241402758cf2a86e5568a28da0942e1810fe12c324 |
| sha256 | dd29536b27649fa897d39198f3ec32d05215b9c6d2864acc32f51de648a25e25 |
| sha1 | b7119d01b2e49938ac310543e7240815e26b711c |
| sha1 | f9d075fc57b6b27a6066734a9a9ba25d666ba9db |
| md5 | 405186a1740ede3e8c56bbf81c043e7e |
| md5 | 6971a368b4164f8d53a9041b717e8ace |
| md5 | 87e8479ef75eb55bf7a09ca6b8a60c49 |
| path | %APPDATA%\Microsoft\Windows\Libraries\Cache\steamwebhelper.exe |
| path | %APPDATA%\MyApp\y.dat |
| path | %APPDATA%\MyApp\y.ps1 |
| filename | x.exe |
| filename | y.ps1 |
5 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.
Do not block
These values came out of this investigation, but blocking them would break something legitimate, whether a shared service, a bystander's infrastructure, or the victim's own equipment. They are listed here because they still matter for hunting, and they are deliberately excluded from the copy and download buttons above.
| Type | Indicator | Why it stays off a blocklist |
|---|---|---|
| ipv4 | 202.71.14.31 |
Host of the first-stage script and the second-stage executable named in the clipboard command |
| domain | newdouble-authentification.com |
Fake verification lure page |
| domain | newdoubleauthentification.com |
Fake verification lure page |
| url | http://202.71.14.31/x/x.exe |
Second-stage executable URL configured inside the script |
| url | http://202.71.14.31/y/ |
Open directory listing on the payload host; it lists one file, y.ps1 |
| url | http://202.71.14.31/y/y.ps1 |
First-stage script URL placed on the clipboard by the lure page |
| sha256 | f6afe770a78d3655c367819b0c5e8afb623cf56b9922c179efbc89fea1a9ea86 |
Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose. |
| sha1 | 17602aa32d21a7bba16e1c657b4a818463fc560a |
Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose. |
| md5 | 3b5072ed500f8d2a34027ed6ea7f0a30 |
Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose. |
| md5 | 83cb3b733cad23c702777baa42efaca3 |
Module stored inside x.exe (carved at file offset 0x1B1C50, PE64 DLL, 400,896 bytes). It exists as its own file only in an analysis carve, so on a host it appears in process memory, not on disk. Use these values as memory-scan and YARA seeds. Never load them into a file-hash blocklist: a disk hash match cannot occur, and the values are held apart from the indicator buckets on purpose. |
Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.