MALWARE on a BLOCKCHAIN! | Malware Analysis of ClearFake hosed on hacked WordPress sites

Опубликовано: 11 Апрель 2026
на канале: Jai Minton - CyberRaiju
1,371
76

Analysis of ClearFake malware which is planted on compromised WordPress websites to convince unsuspecting visitors to download and run malware.

** Find me at **
Twitter/X -   / cyberraiju  
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju

** Tools **
FLARE VM - https://github.com/mandiant/flare-vm
Detect-It-Easy - https://github.com/horsicq/Detect-It-...
Deobfuscate for Obfuscator.io - https://obf-io.deobfuscate.io/
Publicwww - https://publicwww.com/
Urlscan - https://urlscan.io/
Rapid7 IDAT Loader Extractor - https://github.com/rapid7/Rapid7-Labs...
Yara - https://github.com/VirusTotal/yara/re...
Yara Rule - https://github.com/JPMinty/Detection_...
FLOSS - https://github.com/mandiant/flare-floss
pestudio - https://www.winitor.com/download

** Sample **
https://bazaar.abuse.ch/sample/ad6a8f...
https://bazaar.abuse.ch/sample/384d11...

* IDAT Loader Analysis*
Part 1 -    • This ANTIVIRUS runs MALWARE | Malware Anal...  
Part 2 -    • MALWARE ANALYSIS | Reversing IDAT (Hijack)...  

** Website Scans **
https://urlscan.io/search/#bsc-datase...
https://urlscan.io/result/269a495e-be...
https://urlscan.io/result/42c40952-f9...

** Further Reading **
https://rmceoin.github.io/malware-ana...
https://blog.sekoia.io/clearfake-a-ne...
https://www.rapid7.com/blog/post/2023...
https://bscscan[.]com/address/0x34585777843Abb908a1C5FbD6F3f620bC56874AA
https://docs.soliditylang.org/en/v0.4...
https://en.wikipedia.org/wiki/Smart_c...

** Timestamps **
00:00 - Intro
00:14 - ClearFake Summary
00:45 - Sekoia Blog Post
01:12 - ClearFake Attack Chain
01:50 - Smart Contract Analysis
02:56 - Interacting with a Smart Contract
04:25 - Analysing Smart Contract Response
05:30 - Domain Pivot via Urlscan.io
06:30 - Analysing Potentially Compromised Websites
07:52 - Analysing ClearFake Phishing Page
09:00 - Multi-language Phishing Support
10:00 - Payload in HTML Content
10:38 - Another Compromised Website
11:38 - Analysis of BLUE.ps1
13:28 - Base64 PowerShell Script Analysis
14:20 - AES Decryption in CyberChef
17:20 - Final Downloader Analysis
18:23 - Final Malware Analysis
21:05 - Hunting for IDAT Loader
22:24 - Extracting Final Payload
22:55 - Identifying Malware Loaded by ClearFake
24:32 - Summary
25:07 - Outro

Credits:
SFX by Pixabay