Skip to content

Campaign record

Emmenhtal Loader inside an MP3

Emmenhtal loader delivered as a booby-trapped MP3 and followed by Lumma Stealer

Status as last assessed
Active
First seen
Unrecorded
Last seen
2025-05-19
Indicators
11
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Emmenhtal Loader
  • Lumma Stealer

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Trend Micro's managed detection team traced a delivery chain that opens with a counterfeit human-verification page. The visitor is told to paste an mshta command, which fetches what looks like an ordinary audio track. The track really does play music, but it also carries JavaScript wrapped first in base64 and then in hexadecimal, which Trend Micro attributes to the Emmenhtal loader. Unwrapping it starts a hidden PowerShell process that pulls down a second script disguised with a spreadsheet extension, injects code into svchost.exe and reaches a command server on port 8587. Lumma Stealer follows, together with DLL sideloading from a browser-updater executable dropped into a user profile directory, and a browser launched on a throwaway profile against a local listener. Several of the audio files were sourced from a royalty-free music library and modified.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
PowerShell19 of 4443%T1059.001
mshta.exe7 of 4416%T1218.005

Both of these mechanisms appear together in 4 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

11 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: download2431 dot mediafire dot comdomainDownload URLShared platformReport an error in domain record 349a4a9d-3ca4-48b3-9565-916c315ea8a9
url, shown defanged for safety: hxxps colon slash slash ernier dot shop/lyricalsync dot mp3urlPayload hostNot yet assessedReport an error in url record f0e02ccf-b3c1-4260-b70b-cbbe9ea21d73
url, shown defanged for safety: hxxps colon slash slash yedik dot shop/Tech_House_Future dot mp3urlPayload hostNot yet assessedReport an error in url record 3d702054-bdbf-4440-a9e0-a7edf6b52c5e
url, shown defanged for safety: hxxps colon slash slash zb-files dot oss-ap-southeast-1 dot aliyuncs dot com/DPST_doc dot mp3urlPayload hostShared platformReport an error in url record 8bd5c5a4-275c-4784-9d5d-6039623e4056
ip, shown defanged for safety: 176 dot 65 dot 141 dot 165ipCommand and controlNot yet assessedReport an error in ip record a23ef30b-8c00-4299-9651-7f4305bccb4d
domain, shown defanged for safety: bi dot yuoie dot shopdomainStagingNot yet assessedReport an error in domain record d139ba5c-311d-4354-82d8-d8471f470990
url, shown defanged for safety: hxxps colon slash slash bi dot yuoie dot shop/750413b4e6897a671bc759e04597952a0be747830189873b dot xlsxurlStagingNot yet assessedReport an error in url record edc478d9-2c39-4775-a833-f4eb776b1f68
filename, shown defanged for safety: 750413b4e6897a671bc759e04597952a0be747830189873b dot xlsxfilenameSampleNot yet assessedReport an error in filename record a06eca90-cab4-40c5-b0a0-15662b88cec1
filename, shown defanged for safety: lyricalsync dot mp3filenameSampleNot yet assessedReport an error in filename record e72ba32c-8de9-4447-b9f4-f991a8a45e5c
sha1, shown defanged for safety: 3e2794400664f6ae9a9b27821bf01ca008f99e1dsha1SampleNot yet assessedReport an error in sha1 record 35f10017-4c7d-4557-a21e-6ddb5387a26c
domain, shown defanged for safety: buyvault dot shopdomainOtherNot yet assessedReport an error in domain record 0cb0bd63-1f3d-41ef-a51c-b434108e1f23

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Emmenhtal Loader inside an MP3”, campaign ID deeaf6a4, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/deeaf6a4/emmenhtal-mp3-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.