A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

Sekoia's Threat Detection & Research team analyzed¹ ErrTraffic, a fast-growing ClickFix malware distribution framework sold as a Malware-as-a-Service offering by a threat actor known as LenAI. The framework injects malicious JavaScript into compromised WordPress sites, showing visitors lures that trick them into running PowerShell commands that infect their machines with malware.

The original analysis publicized 71 domain IoCs. Aided by the WhoisXML API MCP Server², we investigated those 71 domain IoCs after confirming none were owned by legitimate entities.

71

Original IoCs Analyzed

Domain IoCs extracted from the network indicators

Key Findings

12

Email-connected domains

16

Additional IP address

156

IP-connected domains

56

Malicious Articfacts

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Domain IoC legitimacy check
  • Client traffic and typosquatting analysis
  • Domain IoC WHOIS and DNS history analysis
  • Email-connected domain discovery
  • IP and IP-connected domain discovery
  • String-connected domain discovery

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started