TL;DR
pcalua.exe and mshta.exe, AES-256-CBC decryption, and HKCU Run key persistence. Beaconing is designed to resemble CDN traffic and the malware can re-obfuscate itself by receiving modified source code from C2.CfgHelper and CfgMgr tasks, and maintains a loader → modules chain.FileR.txt, compiles C# payload in memory, bypasses UAC, and installs ScreenConnect as a service.
Sample: ANY.RUN
ETHERRAT is a Node.js-based backdoor that leverages the EtherHiding technique to retrieve and update its command-and-control (C2) infrastructure via Ethereum smart contracts. It uses CDN-like HTTPS beaconing to blend malicious traffic with legitimate services and supports remote command execution, system profiling, and theft of crypto wallets and cloud credentials.
How to detect: Detected by monitoring abnormal file activities and command lines.
Key facts:
pcalua.exe to proxy execution of mshta.exe, which retrieves and runs a malicious HTA script.setString to redirect infected hosts./api/ + random hex + UUID + fake static file extensions such as .png, .jpg, and .css, with query parameters like id, token, and key; communication occurs over HTTPS/TLS 1.3.Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion | VT First Submission |
|---|---|---|---|---|
| 2026-04-06 | esentire.co | 2026-04-06 | 0 | 2026-04-06 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"set r=%RANDOM%%RANDOM%%RANDOM%%RANDOM%" OR threatName:"etherrat"
IOCs:
a27fe395b51d1cca93bf609a97d53013e94e1dd90166fc4483d334f183eb814a6fad8f53a7583b6ee9be41c80b2b564aed8bfdbd6a7e5a63f5e3cf312a43aaa6MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.001 | Command and Scripting Interpreter: PowerShell | Starts POWERSHELL.EXE for commands execution. |
| T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Starts CMD.EXE for commands execution. |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Changes the autorun value in the registry. |
| T1564.003 | Hide Artifacts: Hidden Window | Runs PowerShell with an invisible window. |
| T1082 | System Information Discovery | Lists computer manufacturer and model. |
| T1135 | Network Share Discovery | Starts NET.EXE to display or manage information about active sessions. |

Sample: ANY.RUN
OCRFix is a malware loader and botnet component used in the EtherHiding chain to deliver and execute additional payloads. It is distributed through malicious websites and uses a multi-stage loading flow with configuration retrieval from blockchain infrastructure on Binance Smart Chain. After infection, it deploys modules, establishes persistence through scheduled tasks, and periodically pulls updates or new components. Its main purpose is stealthy delivery of the next stage and remote control of the system.
How to detect: Detected by characteristic artifacts and persistence mechanisms, including C:\ProgramData\app_config\configpackT.zip, C:\Users\admin\AppData\Local\update_data.zip, and scheduled-task creation for CfgHelper and CfgMgr.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion | VT First Submission |
|---|---|---|---|---|
| 2026-03-23 | derp.ca | 2026-04-07 | 61 | 2026-02-28 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"\\app_config\\configpackT.zip" OR filePath:"C:\\Users\\admin\\AppData\\Local\\update_data.zip" OR commandLine:"/create /tn *CfgHelper*" OR commandLine:"/create /tn *CfgMgr*"
IOCs:
C:\ProgramData\app_config\configpackT.zipC:\Users\admin\AppData\Local\update_data.zipCfgHelperCfgMgrMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1053.005 | Scheduled Task | Creates tasks CfgHelper and CfgMgr for regular execution. |
| T1105 | Ingress Tool Transfer | Downloads additional modules and updates. |
| T1071.001 | Web Protocols | Uses internet/blockchain for configuration retrieval. |
| T1027 | Obfuscated/Compressed Files | Stores payload in ZIP archives such as configpackT.zip and update_data.zip. |
| T1547 | Boot or Logon Autostart | Persists through the task scheduler. |
| T1036 | Masquerading | Uses names like CfgHelper and CfgMgr. |
| T1496 | Resource Hijacking | May use the system as part of a botnet. |

Sample: ANY.RUN
SILENTCONNECT is a multi-stage Windows loader that uses VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy ScreenConnect on victim hosts. The infection chain starts from a lure page with a Cloudflare Turnstile CAPTCHA, downloads a VBScript, retrieves a C# source payload, compiles it in memory, and finally installs ScreenConnect. The campaign also uses trusted hosting and delivery infrastructure such as Google Drive and Cloudflare object storage.
How to detect: Detection based on identifying artifacts such as C:\Windows\Temp\FileR.txt and execution of a command matching HelloWorld -> SayHello(), together with the associated PowerShell/C# download-and-execute chain.
Key facts:
Replace() and Chr() to hide the next stage.FileR.txt to C:\Windows\Temp\ and then compiles and runs the C# payload in memory through Add-Type and [HelloWorld]::SayHello().NtAllocateVirtualMemory, runs shellcode to recover the PEB, and uses PEB masquerading by rewriting its own module name and path to winhlp32.exe and c:\windows\winhlp32.exe.CMSTPLUA COM interface and adds a Microsoft Defender exclusion for .exe files.curl.exe and msiexec.exe, and the installed client persists as a Windows service and beacons to the actor-controlled ScreenConnect server over TCP port 8041.download_invitee.php, which made infrastructure tracking easier.Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-03-31 | elastic.co | 2026-04-06 | 18 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"C:\\Windows\\Temp\\FileR\\.txt"
IOCs:
8bab731ac2f7d015b81c2002f518fff06ea751a34a711907e80e98cf70b557dbd6c8bdd4e8b6d64f619c0277b26fa68c6117dae36bb9a3707b4d89d4a88e343a225e08c08d3664d6acb586d5966a0c3e7d2e26f8fc399e51401f41759ef9d426d4ea4170e3fc909ca0224926bf3a161e25100a432b1740fe20535e7d9b8bfc1cb6e5ede61684a2246797a01a6b6aeb8f99603044abb8a23663da0395edf6f20a9151b980b245d1958edf7af62fc772ad1553c7de68cffe535f2f7f3c536895df57b795c477b2939d96dfe59147ad8fd5d7228a2b7330119f04b59eff4d2fc842f45f2aa75aff84dd02d903feee56f44a316b72a8e42455f87b0c395df525e8272ed3d6e02b99b433e07cf382b93c4df0356530f16ad26eed380e5bf8bbe8968c7577ae95e892eda34e00304308715c65a197216854a85cecfbfd402a3a8964e01dfe062f6413a6dece21ac3e993d9b76a472dd1c8f6a01adaa76ba9e9a19487d4259f7efcf96a38f7c74be9187e0be57d54e8d0cd33bf9355d8f42b60555cb4fd59b286542d7643f665df44deabf74653b7ba84ea72a5ce61a73c739c85d28cefffecd8d1d35f706cfe49c9c62a0448bd65f41db6c73542c12c6d36deff63a60MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.001 | Command and Scripting Interpreter: PowerShell | The VBScript stage launches PowerShell to download and compile the C# payload in memory. |
| T1105 | Ingress Tool Transfer | The loader downloads FileR.txt from Google Drive and later downloads the ScreenConnect MSI. |
| T1027 | Obfuscated Files or Information | The VBScript uses Replace() and Chr() for obfuscation, and the C# payload uses constant unfolding. |
| T1548.002 | Abuse Elevation Control Mechanism: Bypass User Account Control | The loader attempts a UAC bypass via the CMSTPLUA COM interface. |
| T1562.001 | Impair Defenses: Disable or Modify Tools | The script adds a Microsoft Defender exclusion for .exe files. |
| T1219 | Remote Access Software | The final payload is ScreenConnect, deployed as an RMM tool for remote control. |
ETHERRAT stands out through its blockchain-backed C2 updates, CDN-like HTTPS beaconing, and the combination of ClickFix delivery and proxy execution through pcalua.exe and mshta.exe.
OCRFix is most reliably identified by the paired ZIP artifacts and its scheduled-task persistence, especially the CfgHelper and CfgMgr task names.
SILENTCONNECT leaves a strong execution trail through C:\Windows\Temp\FileR.txt, in-memory PowerShell/C# execution, and the final ScreenConnect installation chain.
Across all three families, the most effective hunting strategy is to combine file artifacts, command-line patterns, and persistence behavior with the network indicators listed above.