Known malicious kitcriticalphishing
ClickFix FakeCAPTCHA — LOLBin variant (msiexec/mshta/wmic/etc.)
family: clickfix-fakecaptcha
Same fake-CAPTCHA flow as the PowerShell variant but the copied command is a non-PowerShell Windows LOLBin (msiexec /i <URL>, mshta, wmic, certutil, regsvr32, curl, iex, Invoke-Expression). First validated live on 00c29c34fd.nxcli.io from threatfox's IClickFix-tagged feed (scan 52b189eb / 2f465516 / f6c071f8). Markup-tolerant string matchers (<b>R</b> / <b>V</b> / <b>Enter</b>) catch kits whose instruction text is HTML-formatted.
Anchors
YARA ruleDetect_ClickFix_FakeCaptcha_LOLBin
Provenance
Added: 2026-05-27 10:49
YARA-anchored. Sister to the PowerShell rule under the same family slug.
Sightings (7)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| norediam.com | ca791ac9… | https://norediam.com/traffic/api | yara | 2026-08-26 12:42 |
| norediam.com | 444ecfbf… | https://norediam.com/traffic/api | yara | 2026-08-26 11:21 |
| norediam.com | a7182413… | https://norediam.com/traffic/api | yara | 2026-08-26 07:23 |
| gangesjute.com | e33f85f1… | https://gangesjute.com/wp-content/plugins/one/assets/js/captcha-loader.js?ver=2.0.0 | yara | 2026-08-15 03:10 |
| 00c29c34fd.nxcli.io | f6c071f8… | https://00c29c34fd.nxcli.io/#html | yara | 2026-05-27 10:47 |
| 00c29c34fd.nxcli.io | 2f465516… | https://00c29c34fd.nxcli.io/#html | yara | 2026-05-27 10:43 |
| 00c29c34fd.nxcli.io | 52b189eb… | https://00c29c34fd.nxcli.io/#html | yara | 2026-05-27 10:43 |