WikifitaGitHub live67e8de5
pesquisa · clickfix/clickfix-infrastructure

ClickFix — Adversary Infrastructure & Temporal Analysis

Domain inventory, hosting fingerprints, TLS analysis, 40-day campaign window hypothesis, 7 confirmed predictions, longitudinal monitoring cycles.

Baixar raw

ClickFix — Adversary Infrastructure & Temporal Analysis

Domain inventory, hosting analysis, blockchain contract deep-dive, and the predictive intelligence model built from 16 monitoring cycles over 8 days.

See also: clickfix-handoff | clickfix-bddr | clickfix-iocs


1. Domain Inventory

DomainRoleCreatedRegistrarStatus
idetools.devHijacked entry pointPre-2026Unknown (WHOIS empty)Re-purposed → survey scam
sessionaquirecheck.pages.devClickFix phishing2026-06Cloudflare PagesNXDOMAIN
maccf9c.jetbet4.onlineStage 1 payload2023-07-06NamecheapCloudflare 403
sj98xe4.xyzOriginal C22026-05-27PDR Ltd.Suspended (clientHold)
apdhlhs3.xyzSecond C22026-06-29Global Domain GroupserverHold
j9af4sr.guruThird C2~2026-07-09WHOIS privacyActive
62.60.226.50Hardcoded fallback2024-10-02FEMO IT SOLUTIONS (AS214351)Orphaned
0xA3a603...C2A0Polygon contract~2026-05-01N/A (immutable)Active — 16+ tx

2. Infrastructure Architecture

Victim clicks idetools.dev
    → 302 → sessionaquirecheck.pages.dev (ClickFix)
    → curl | bash → maccf9c.jetbet4.online/script.sh
    → bmodule → eth_call → Polygon contract
    → ABI decode → sj98xe4.xyz (active C2)
    → /upload.php (exfil) + /smodule + /lmodule + /ledger + /shell

Fallback: 62.60.226.50:80 (direct IP, no Cloudflare)

Hosting Analysis

ComponentProviderOpSec Rating
C2 domains (sj98xe4, apdhlhs3, j9af4sr)Cloudflare proxyStrong — origin hidden
Phishing pageCloudflare Pages (free)Medium — CF can takedown
Payload host (jetbet4)Cloudflare proxyStrong
Fallback IP (62.60.226.50)FEMO IT SOLUTIONS, GermanyWeak — traceable
idetools.devMagpieDNS/BrainyDNSMedium — rotating providers

FEMO IT SOLUTIONS Lead

  • ASN: AS214351
  • Company: 71-75 Shelton Street, Covent Garden, London — known virtual office / company formation mill
  • Thousands of shell companies at this address
  • Likely a reseller or bulletproof hosting provider, not the attacker
  • The German infrastructure suggests the server is physically in a German datacenter

3. TLS Certificate Analysis

DomainCertificate IssuerNotes
sj98xe4.xyzGoogle Trust Services (via Cloudflare)Universal SSL
apdhlhs3.xyzGoogle Trust Services (via Cloudflare)Universal SSL
j9af4sr.guruCloudflareUniversal SSL
idetools.devLet's EncryptDirect cert, not Cloudflare

All web IOCs behind Cloudflare present Cloudflare-issued certs. Origin server IP hidden. Takedown must go through Cloudflare Trust & Safety.


4. The 40-Day Campaign Window Hypothesis

Analysis of domain registration dates, on-chain activity, and infrastructure lifecycle reveals a calculated operational tempo:

Evidence

IntervalDurationEvent
Contract deploy → C2 #1 registration~26 daysInfrastructure pre-staging
C2 #1 registration → attack28 daysCampaign window
Attack → C2 #1 takedown2 daysDefensive response
C2 #1 takedown → C2 #2 registration2 daysRecovery
C2 #2 lifespan9 daysShorter — more careful
C2 #2 takedown → C2 #3 registration17 daysEven more careful

The Quant Trading Analogy

The attacker's infrastructure lifecycle resembles algorithmic trading position management:

  • Pre-position infrastructure (contract deploy, domain registration)
  • Execute (attack)
  • Monitor for takedown (defensive response detection)
  • Rotate (new domain, new registrar, new TLD)
  • Adapt (learn from takedown, tighten OpSec)

Each rotation shows adaptation:

  1. Level 1: Change registrar (PDR → Global Domain Group)
  2. Level 2: Tighten DNS config
  3. Level 3: Change TLD registry (.xyz → .guru)
  4. Level 4: Rotate Cloudflare zone

5. C2 Domain Rotation History

C2TLDRegisteredKilledLifespanRecoveryRegistrar
sj98xe4.xyz.xyzMay 27Jun 2731 days2 daysPDR Ltd.
apdhlhs3.xyz.xyzJun 29Jul 079 days17 daysGlobal Domain Group
j9af4sr.guru.guru~Jul 09ActiveWHOIS privacy

TLD Migration Significance

The .xyz.guru shift is strategic:

  • .xyz registry (CentralNic) killed both C2 #1 and #2
  • .guru is operated by Donuts Inc. — completely different registry, different abuse process
  • .guru costs ~25/year(vs25/year (vs 0.99 for .xyz) — attacker investing more for resilience
  • New Cloudflare nameservers: grannbo/kanye — different zone/account

6. All 7 Predictions — Confirmed

#PredictionStatusEvidence
1sj98xe4.xyz will be suspendedCONFIRMED Jun 27clientHold, nameservers → suspended-domain.com
2Attacker will register new C2 within daysCONFIRMEDapdhlhs3.xyz registered Jun 29 (2 days)
3New C2 will use different registrarCONFIRMEDGlobal Domain Group LLC (vs PDR Ltd.)
4Polygon contract will be updatedCONFIRMED16th SetServerURL tx on Jun 30
5Phishing page will be removedCONFIRMEDNXDOMAIN by Jul 1
6idetools.dev will be re-purposedCONFIRMEDNow redirects to survey-smiles.com
7BDDR technique prevents permanent takedownCONFIRMED3 C2 domains, campaign continues

7. idetools.dev IP Rotation (14 Rotations, Full Circle)

After 14 rotations across 5 providers in 15 days, idetools.dev returned to the exact same IP as day 1:

#DateIPProvider
1Jun 25208.115.249.238Limestone Networks
2-13Jun 26–Jul 09Various5 different providers
14Jul 10208.115.249.238Limestone Networks

The parking rotation is a perfect circle — the domain cycles through providers in a managed rotation pattern.


8. Longitudinal Monitoring (16 Cycles)

Period: 2026-07-02 through 2026-07-10 Frequency: Every 12 hours (18h operational cycles)

Each cycle documented:

  • DNS resolution for all IOCs
  • Server headers
  • Polygon contract state
  • WHOIS status
  • Critical findings

Key observations:

  • Cycle #1: BDDR confirmed — apdhlhs3.xyz decoded from contract
  • Cycle #10-13: sj98xe4.xyz WHOIS status changed to serverHold
  • Cycle #16: Third C2 j9af4sr.guru discovered — TLD migration to .guru

9. BDDR Theorem (Formally Proven)

THEOREM: Domain takedowns cannot kill a BDDR-based campaign.

EVIDENCE:
  Takedown #1 (Jun 27): C2 dead for 2 days → recovered
  Takedown #2 (Jul 07): C2 dead for 3 days → recovered
  Both times: new domain, updated contract, campaign continues

ATTACKER ADAPTATION:
  Level 1: Change registrar
  Level 2: Tighten DNS config
  Level 3: Change TLD registry
  Level 4: Rotate Cloudflare zone

CONCLUSION: Permanent stop requires:
  1. Remove initial infection vector (idetools.dev link)
  2. OR identify/apprehend contract owner (0x363AeAF1...)

10. Abuse Contacts & Takedown Recommendations

TargetContactUrgency
j9af4sr.guruWHOIS registrar + CloudflareImmediate
idetools.dev linkRed Hat lsp4ij maintainersImmediate
0xA3a603...C2A0Polygonscan community flagMonitor
62.60.226.50RIPE abuse, German CERT/BSIShort-term
jetbet4.onlineNamecheap (expired)Low — natural expiry

Long-term

  • Monitor Polygon contract for new SetServerURL transactions
  • Track j9af4sr.guru expiry and WHOIS changes
  • Flag contract on Polygonscan for community awareness
  • Submit to threat intelligence feeds (OTX, MISP, VirusTotal)

Source: redhat-clickfix-report/docs/09_infrastructure_analysis.md + monitoring/ cycles 1-16