Automatically translated.View original post

ClickFix Fake Blue Screen Tricked Victims into Installing Malware

ClickFix, this time using a fake blue screen, tricked the victim into installing malware as ordered on the screen.

The strategy of tricking the victim to correct a fake error to embed malware into the victim machine, or ClickFix, is known as a popular method that is being widely used in many different ways, and this time the strategy comes with a new method of tricking the victim.

According to a report by the website Bleeping Computer, a new method of ClickFix deception has been detected, which typically uses fake Captcha on hacked websites or hacker fake websites to trick victims into following Captcha, but this time it is a fake BSOD or Blue Screen of Death with instructions for the victim to follow to correct the screen, which, if the victim follows, eventually leads to malware infection.

This new type of campaign scam starts with hackers tricking victims into fake websites that make imitations of Booking.com, which are websites for hotel reservations. These fake websites often use domain names such as' low-house [.] com '. After the victim enters the site, after the victim has surfed the site for a while, there will be a pop-up screen warning that "Loading is taking too long" or that the loading is too long. This is a JavaScript operation embedded on the site. If the victim clicks the button on the bounce screen, the fake screen will be turned on. The screen came up immediately.

In this fake screen, the victim will turn on Run, a feature for running the code, using the Windows + R logo button. After that, in the next step, the screen will instruct the victim to press the CTRL + V button to automatically paste the malware code that the script copied. In the end, the victim will press OK or enter button to run the code. If the victim believes it will be immediately infected with malware. These steps will not be different from any other form of ClickFix scam, but only with the panic of the appearance of the sky screen for the victim. It's only easier to get fooled.

As for the code, the research team determined that it was a code in the form of a PowerShell script that would lead to the reopening of the fake Admin Panel of the fake Booking website to deceive the victim, while in the background it would download the first payload file. NET project (v.proj) is codified with a Windows tool called MSBuild.exe, and after the code in the file has been successfully executed, the malware will add itself and related files to the Exclusion List of Windows Defender protection tools, and then send a Prompt command to the UAC or User Account Control to gain access to the system at a high level, and then download the malware through a tool called Background Intelligent Transfer Service (BITS), which will be created at this stage. Persistence by placing a .Url file in the Startup folder to guarantee that the malware will run on the system at any time and then downloading the real malware file called staxs.exe on the machine.

This file is a remote access Trojan file called DCRAT. This malware will shoot its own code into a process called 'aspnet _ compiler.exe' with the technique of replacing Process code with malware code or Process Hollowing to run it directly on memory, making it difficult to detect, followed by contacting the C2 or Command and Control server to send the victim system specifications back to the server and waiting for the next command from the server.

This malware can be called capable of desktop control, keylogging, RevereseShell, and running other payloads directly on memory. The research team found that the malware used this method to release malware type, use the victim's machine resources to mine Krypto Kerrenzi coins, or Crypto Miner.

The research team has warned that the genuine Windows screen does not command users to press the Edit button. The screen only shows error codes and warnings to reboot the system. If you find a screen with strange commands, do not believe and follow.

# Trending # Lemon 8 Howtoo # Drug sign with lemon8 # lemon 8 diary # freedomhack

1/27 Edited to

... Read moreในยุคนี้ภัยไซเบอร์นั้นพัฒนารูปแบบได้ซับซ้อนและเนียนมากขึ้นเรื่อยๆ อย่างกรณี ClickFix ใช้จอฟ้าปลอมลวงเหยื่อที่ไม่คุ้นเคยกับระบบ Windows เรื่องจอฟ้าแห่งความตาย (Blue Screen of Death) ซึ่งหลายคนเห็นแล้วเกิดความตื่นตระหนกจนคล้อยตามคำแนะนำที่แสดงขึ้นมาทันที ประสบการณ์ในการรับมือภัยแบบนี้คือ อย่าหลงเชื่อหน้าจอแจ้งข้อผิดพลาดที่มาพร้อมกับคำสั่งให้ทำอะไรเลย เพราะ Windows จริงๆ จะไม่ให้เรากดปุ่มใดๆ เพื่อแก้ไขโดยตรงผ่านหน้าจอดังกล่าว แต่จะรีบูทเครื่องใหม่โดยอัตโนมัติ พร้อมแสดงรหัสข้อผิดพลาดให้เรานำไปค้นหาวิธีแก้ไขแทน สิ่งสำคัญอีกอย่างที่ช่วยป้องกันคือการระมัดระวังเว็บที่เข้าใช้งานโดยเฉพาะเว็บไซต์แปลกๆ หรือโดเมนที่ไม่คุ้นเคยอย่าง 'low-house.com' ซึ่งมักจะปลอมแปลงเป็นเว็บไซต์ยอดนิยมอย่าง Booking.com เพื่อหลอกหลวงให้คลิกลิงก์หรือป้อนข้อมูลส่วนตัวได้ นอกจากนี้ ควรอัปเดตระบบปฏิบัติการและโปรแกรมแอนตี้ไวรัสอย่าง Windows Defender ให้เป็นเวอร์ชั่นล่าสุด เพื่อช่วยตรวจจับและป้องกันมัลแวร์ที่ใช้เทคนิคหลบเลี่ยงการตรวจจับ เช่น การฝังตัวใน Process หรือ Process Hollowing และการใช้ความสามารถ Remote Access Trojan (RAT) เพื่อเข้าควบคุมเครื่องนั่นเอง จากการวิเคราะห์มัลแวร์ DCRAT ที่ทีมวิจัยพบ นอกจากจะดักจับข้อมูลและสั่งการคอมพิวเตอร์แล้ว มัลแวร์นี้ยังใช้ทรัพยากรเครื่องเพื่อขุดคริปโตเคอร์เรนซี ทำให้เครื่องทำงานช้าลง และเสี่ยงต่อความเสียหายของระบบในระยะยาว การสอนและให้ความรู้แก่ผู้ใช้งานในครอบครัวหรือบริษัทเกี่ยวกับวิธีสังเกตจอฟ้าปลอมและการไม่คลิกลิงก์หรือป้อนคำสั่งใดๆ ที่เจอจาก Pop-up หรือเว็บไซต์ที่ไม่น่าเชื่อถือนั้น เป็นแนวทางที่ช่วยลดความเสี่ยงของการโดนโจมตี สุดท้ายการตั้งค่าระบบ UAC (User Account Control) ให้เข้มงวด และไม่อนุญาตให้รันโค้ดที่ไม่ได้รับการยืนยันสามารถช่วยสกัดกั้นมัลแวร์ก่อนที่จะรันได้อีกด้วย ภัยไซเบอร์ที่ใช้จอฟ้าปลอมอย่าง ClickFix นี้จึงเป็นตัวอย่างที่ชัดเจนว่าผู้ใช้งานควรมีความรู้ความระมัดระวังในการใช้งานอินเทอร์เน็ตและอุปกรณ์เสมอ ไม่ควรตกเป็นเหยื่อของความตื่นตระหนกชั่วคราว เพราะมันอาจนำไปสู่การสูญเสียข้อมูลและความปลอดภัยของคอมพิวเตอร์ได้จริง

Related posts

We were tricked !
* * #dogmom #dachshund #cutepuppy #trending #fyp ≥ #minidachshund #longhairedminidachshund #sausagedog #dogtok
𝓟𝓪𝓽𝓻𝓲𝓬𝓲𝓪 ❥

𝓟𝓪𝓽𝓻𝓲𝓬𝓲𝓪 ❥

5321 likes

4 FOODS U WERE TRICKED TO THINK ARE HIGH PROTEIN✨
By now we all know how important nutrition is to really notice the most progress from your workouts✨Being misinformed on which foods are high quality protein sources is wayyyy more common than it should be! This is mainly due to tricky marketing tactics, but that’s a whole separate story in and of
Cassidy

Cassidy

3687 likes

I think I tricked everyone 😭
#tiktok #youtube #haircut #slayornay
BrookeMonk

BrookeMonk

766 likes

little of both
aint that the truth #husbandandwifecomedy #husbandandwifehumor #marriedlifehumor #marriagegoals #diyhomeprojects
kolterwinton

kolterwinton

24 likes

#shortdramareview #tiktok #fyp #foryoupage #movie
wiaewn

wiaewn

1 like

The Living Statue Mystery ⚠️ #fyp #movie
lovemovie

lovemovie

5 likes

#50cent
5bizztv

5bizztv

10 likes

She Was Tricked Into Slavery: Biddy Mason’s Fight…
#blackcommunity #blackhistory #blacklemon8creator #hiddenhistory #untoldstories Los Angeles
Treexkz Knaxkz

Treexkz Knaxkz

56 likes

Grace getting tricked I think
#fyp #gamingonlemon8 #ps5 #residentevil #residentevilrequiem
jitfromdabangem

jitfromdabangem

0 likes

I tricked him on the last one 😂
#funny #comedy #couples
TKM Familia

TKM Familia

81 likes

the truth is many times these things do roll over many times he can avoid it. It is our responsibility to make sure that doesn’t happen. #greenscreenvideo
Will McC

Will McC

0 likes

#film #movie
Uyjjgfo

Uyjjgfo

174 likes

We tricked her 😂
#funny #comedy #couples
TKM Familia

TKM Familia

76 likes

Would you play a riddle game with me?
Don’tGetTricked

Don’tGetTricked

3 likes

🍋🩷🩵
Tv
Ayden Hernandez

Ayden Hernandez

1 like

Kitten gets swallowed by owner
Minnie maybe getting a little bit too much spa treatment? I typically post riddles and brain games on TikTok but this was just hilariously cute 🥰 😂 #kitty #cat #cutecatalert #adorable
Don’tGetTricked

Don’tGetTricked

2 likes

#usa #foryou #tiktok #fyp #movie
midnightfilms5

midnightfilms5

197 likes

4 FOODS U WERE TRICKED INTO THINKING ARE PROTEIN✨
By now we all know how important nutrition is to really notice the most progress from your workouts✨Being misinformed on which foods are high quality protein sources is wayyyy more common than it should be! This is mainly due to tricky marketing tactics, but that’s a whole separate story in and of
Cassidy

Cassidy

49 likes

A blonde woman with braided hair, wearing a white hoodie and a safety harness, sits in an off-road vehicle with her eyes closed.
The rear of an off-road vehicle (SXS) with two black flags featuring a white silhouette, parked in a sandy desert landscape under a clear sky.
A black and tan off-road vehicle (SXS) with large tires and two black flags is parked in a vast desert landscape under a clear blue sky.
Tricked out sxs
#fyp #offroad #blonde #of
Lemon8er

Lemon8er

278 likes

#greenscreen #greenscreenvideo @Chlo :)
Seema R

Seema R

410 likes

Tricked out Noodles
When your hungry and go to the kitchen and do THE ABSOLUTE MOST!! 😂😂😂😂 Anyways.. Like.. share… follow… THANK YA!! 😘😘
PegTheVegan

PegTheVegan

37 likes

Follow if I tricked you❤️
#dog #dogsoftiktok #dogs #dogsofttiktok #waggywear
Waggy Wear

Waggy Wear

193 likes

Guys I think we were tricked…they told us we couldn’t afford it…those damn liars. Go to Italy. #American #Americans #Italy #Travel #socialexperiment
Jamie Jeffries📲

Jamie Jeffries📲

0 likes

Don’t get tricked
We all have bad days, don’t be tricked into thinking it’s a bad life. Brighter days are always ahead, just keep fighting! #pipjr77 #keepsmiling #fyp #loveya #reels #alwayspositive #humpday #wednesday
pipjr77

pipjr77

23 likes

Give em l-l3ll #explore #fy #trickedme #foryou #arkansas
Lαinα ᥫ᭡

Lαinα ᥫ᭡

14 likes

We tricked #kanyewest in2 lettin me🎤”Gold Digger”
@iamjamiefoxx We tricked #kanyewest into letting me record “Gold Digger”. #jamiefoxx 🎥 @power_106
VSGENT

VSGENT

5 likes

THEY TRICKED YOU TO SELL YOUR ASSETS.
#fyp #crypto #digitalassets #viral #wealthmindset
BankwithJosh

BankwithJosh

1 like

the FBI got tricked and failed America on this tip time to start the abi
brianajacksonhateschompaurora

brianajacksonhateschompaurora

2 likes

Adding pops of color to your style
As a former neutral and dark tone girl I can say stepping into color was intimidating at first, but it made a difference in upgrading my style and not being limited to no color. #fashion #popofcolor #style #fashiontips #colorfulfashion
madelinedonnelson

madelinedonnelson

53 likes

I Tricked Pa Into Giving Me A Hug
La_Breezy_6

La_Breezy_6

0 likes

24/10_ Woke TikToks: MUSIC EDITION! #amalalaernus #foryoupage #fyp #show #repulican
Amala  Ekpunobi

Amala Ekpunobi

17 likes

Quick Riddle Game. Wanna play?
Don’tGetTricked

Don’tGetTricked

0 likes

shawn Elliot

shawn Elliot

8 likes

#candiceswanepoel #victoriasecret
Chat with G (English version)

Chat with G (English version)

1 like

Smdh🤦🏾‍♀️🤣 #fyp #viral #livehighlights
EthikaLover . ♡

EthikaLover . ♡

5 likes

#fypforyou #likesandsaves #comfortovereverything
🌺𝓥𝓲𝓬𝓽𝓸𝓻𝓲a🌺

🌺𝓥𝓲𝓬𝓽𝓸𝓻𝓲a🌺

23 likes

Merry Christmas & happy holidays to all but especially to survivors who are tired but not giving up & survivor parents spreading cheer to their babies & loved ones despite someone trying so hard to fight & destroy them. #healing #lifeafterabuse #dating #holidays
Hedya

Hedya

2 likes

Ejecto SEATO! Cops get tricked!
This is prob one of the more crazy escapes I have ever done in #GTA #gtarp #roleplaying #fivem #gaming let me know in the comments what you think!
Decipherr

Decipherr

7 likes

Practicing More Self Love ✨ @milkmakeup skin tint @Tower 28 Beauty concealer @IT Cosmetics blush @ColourPop Cosmetics eyeshadow pallet @Fenty Beauty contour @Fashion Fair powder bronzer & lip liner @Lancôme mascara
MonicaFitz-MainCharacterEnergy

MonicaFitz-MainCharacterEnergy

47 likes

Wow #fyp #officialfinechina #alexisradcliff #summernoneother #dollybaddiesusa
Lemon8er

Lemon8er

2 likes

See more