A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network
Sekoia's Threat Detection & Research team analyzed¹ ErrTraffic, a fast-growing ClickFix malware distribution framework sold as a Malware-as-a-Service offering by a threat actor known as LenAI. The framework injects malicious JavaScript into compromised WordPress sites, showing visitors lures that trick them into running PowerShell commands that infect their machines with malware.
The original analysis publicized 71 domain IoCs. Aided by the WhoisXML API MCP Server², we investigated those 71 domain IoCs after confirming none were owned by legitimate entities.
Original IoCs Analyzed
Domain IoCs extracted from the network indicators
Key Findings
Additional IP address
IP-connected domains
Malicious Articfacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Domain IoC legitimacy check
- Client traffic and typosquatting analysis
- Domain IoC WHOIS and DNS history analysis
- Email-connected domain discovery
- IP and IP-connected domain discovery
- String-connected domain discovery
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/
- [2] https://main.whoisxmlapi.com/ai/mcp-server