Skip to content

Campaign record

mshta lures fetching remote HTAs

Fake CAPTCHA pages serving remote HTML Applications through mshta

Status as last assessed
Active
First seen
Unrecorded
Last seen
2025-05-19
Indicators
6
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Malvertising
  • SEO poisoning

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Alongside the audio-file cases, Trend Micro's incident data held a run of counterfeit verification pages whose common trait was simply the instruction to paste a line into a system prompt. Each page assembled that line in the browser, decoded it from base64 and placed it on the clipboard, so the visitor never read the destination. Most aimed mshta at a remote HTML Application on a short-lived domain; one used a hidden PowerShell instruction that retrieved a text file and evaluated its contents. Victims arrived through malvertising, through email, and in one investigated case through a poisoned search result for a stately-home visitor attraction, where the top-ranked link was a legitimate website that had been broken into. Trend Micro does not tie these particular hosts to any named malware family.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
mshta.exe7 of 4416%T1218.005

All 3 of these mechanisms appear together in 3 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

6 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: check dot nejyd dot icudomainPayload hostNot yet assessedReport an error in domain record 04e16071-dd32-4817-94bf-15f07656c7a3
url, shown defanged for safety: hxxp colon slash slash ok dot fish-cloud-jar dot us/urlPayload hostNot yet assessedReport an error in url record 9ef8a93e-bbcf-4317-84cd-ba675770e230
url, shown defanged for safety: hxxps colon slash slash w19-seasalt dot com/mbDjBsRmxM1LreEp dot htmlurlPayload hostNot yet assessedReport an error in url record a92d7aa0-2d22-488d-b568-0780059f7ba1
url, shown defanged for safety: hxxps colon slash slash welcome12-world dot com/wpDoQRpZt2PIffud dot htmlurlPayload hostNot yet assessedReport an error in url record 00b67f38-e762-4c37-8c53-fbcdbb2eebd1
url, shown defanged for safety: hxxps colon slash slash x63-hello dot live/nF3mXcQ9FVjs1sMt dot htmlurlPayload hostNot yet assessedReport an error in url record f973fad6-2781-4f12-a19c-d09dc17d7aba
domain, shown defanged for safety: fessoclick dot comdomainStagingNot yet assessedReport an error in domain record 5f43685e-30d4-4aa1-b53e-ef23c7467dd4

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “mshta lures fetching remote HTAs”, campaign ID c0b21902, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/c0b21902/fake-captcha-mshta-hta-lures

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.