Skip to content

Latest commit

 

History

History
75 lines (68 loc) · 2.93 KB

File metadata and controls

75 lines (68 loc) · 2.93 KB

CoreSecThree

CoreSecThree is a sophisticated framework first identified on February 17, 2022, and publicly recognized in early 2024. The framework employs an advanced ClickFix technique that leverages social engineering tactics to compromise victim systems through malicious PowerShell execution. Since its inception, CoreSecThree framework and the ClickFix technique have been consistently used to distribute infostealer malware.

The full report is available here.

Indicators of Compromise (IOC)

Wordpress Backdoor Plugin Hashes

SHA256
616336253c0d7d35f9f231144a7a12b267f67bd3e0f707dc8f9f89986197c20c
84db459a948abcded8507fc2a5d57d688c2c472cb6ee781cbb6abe767827a4e9
2789702ff700dd1e0ecc5b6452b6e5983cf25008ae8f610e625fa360c453eab1
ec74ae7a9856b72b74af7c959447efd2d686a1a12106ddd19361664e0b7cea60

Malvertising Domain

xpand-2.com
wlan-optimizer.com
windows-10-update-assistant.com
video-capture-master.world
vbox7-downloader.top
topaz-remask.live
surfast-video-downloader.com
stimulants-worksheet-high-school-psychology.live
sitescope.today
scientific-method-worksheet.icu
reducing-fractions-worksheet.shop
radeon-relive.space
psd-codec.com
protein-synthesis-worksheet.run
periodic-trends-worksheet.top
peek-through.com
pak-urdu-installer.com
kinetic-and-potential-energy-worksheet.bet
hdd-low-level-format-tool.com
filesplit.digital
file-lister.bet
electron-configuration-worksheet.space
disney-crossy-road.icu
data-lifeguard-diagnostic-for-windows.com
counting-atoms-worksheet.digital
coterminal-angles-degree-and-radian-worksheet.world
conflict-global-terror.shop
cff-explorer.com
breakers-unlock-the-world.run
backupcontrol.snobmail.com
atomic-structure-worksheet.today

Cloudflare Worker Domain

https://villasalterakaiomy.toreain-samaota-1985.workers.dev/
https://tastyrazorsimple.tia-garcia-1986.workers.dev/
https://sensadormazzotti.natasha-hines-1980.workers.dev/
https://pleasedtrooperoctal.chris-plumley-1981.workers.dev/
https://tempemoondognonraid.steve-mccutcheon-1999.workers.dev/
https://surfacesprasadyamamoto.messimo3289.workers.dev/
https://sedtsuitedesnips.mimarylyn2004.workers.dev/
https://guiltyspinnermeter.oktomir4163.workers.dev/
https://decoderskullphilco.tevisyloki.workers.dev/
https://versinlinksiaru.jeterawa1982.workers.dev/
https://patientsimagicdayton.xyfolic.workers.dev/
https://stillsgreytables.debovypy.workers.dev/
https://almostfbodydecker.cihuzulozu.workers.dev/
https://rubydeadpilots.ruqamis.workers.dev/
https://bocesblogspotmyspace.lusazujimi.workers.dev/
https://messingjacobiholster.gipesyqora.workers.dev/
https://spinnerlegacyintitle.fokyrylefy.workers.dev/
https://ethercddokumenthere.ipojyduc.workers.dev/
https://sharpestubcdwikifemale.agehowofu1990.workers.dev/
https://irdahoodcityfaulty.ihesexar.workers.dev/