ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV
A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection.
AI Analysis
Technical Summary
The ClickFix campaign variant uses social engineering to induce victims to run commands via the Windows Run dialog, leveraging rundll32.exe to execute remote payloads over WebDAV tunneled through HTTPS port 443. Payloads are invoked by ordinal export #1, not by named functions, complicating detection. The campaign features evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade automated detection. It also abuses trusted Windows binaries such as pcalua.exe to disrupt process lineage tracking. No files are written to disk during the attack, making traditional file-based detection ineffective. The campaign has successfully exfiltrated browser credentials and sensitive documents. The most advanced variants have bypassed automated EDR detection and were identified only through focused threat hunting on ordinal execution techniques.
Potential Impact
The campaign enables attackers to execute remote payloads without dropping files to disk, evading many traditional detection mechanisms. It results in credential theft and exfiltration of sensitive documents (approximately 13MB). The use of trusted Windows binaries and obfuscation techniques complicates detection and forensic analysis. The threat has not been observed exploiting a specific vulnerability but relies on social engineering and abuse of legitimate Windows functionality.
Mitigation Recommendations
No official patch or fix is available as this is a social engineering and living-off-the-land technique rather than a software vulnerability. Mitigation should focus on user awareness training to resist social engineering attempts, monitoring for unusual use of rundll32.exe and pcalua.exe, and proactive threat hunting for ordinal execution patterns and WebDAV connections over HTTPS. Endpoint detection and response (EDR) solutions should be tuned to detect these behaviors, although the most obfuscated variants may evade automated detection. Network controls could consider monitoring or restricting WebDAV traffic tunneled over HTTPS if feasible. Since no files are dropped, file-based detection is ineffective.
Indicators of Compromise
- hash: f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6
- domain: gentletouchchiropracticclinicauroracol.com
- domain: hcwjcope.poundbahis.com
- domain: uttepcheweaxtowxdj.gentletouchchiropracticclinicauroracol.com
- domain: vqrlwsmzu.webyek.com
- hash: 5ef7bf4ed52be2a6d5ebbcf3076fba5f
- hash: 9e03e983e26d4782a3fef0a6ebb47fdcd46974c9
ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV
Description
A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ClickFix campaign variant uses social engineering to induce victims to run commands via the Windows Run dialog, leveraging rundll32.exe to execute remote payloads over WebDAV tunneled through HTTPS port 443. Payloads are invoked by ordinal export #1, not by named functions, complicating detection. The campaign features evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade automated detection. It also abuses trusted Windows binaries such as pcalua.exe to disrupt process lineage tracking. No files are written to disk during the attack, making traditional file-based detection ineffective. The campaign has successfully exfiltrated browser credentials and sensitive documents. The most advanced variants have bypassed automated EDR detection and were identified only through focused threat hunting on ordinal execution techniques.
Potential Impact
The campaign enables attackers to execute remote payloads without dropping files to disk, evading many traditional detection mechanisms. It results in credential theft and exfiltration of sensitive documents (approximately 13MB). The use of trusted Windows binaries and obfuscation techniques complicates detection and forensic analysis. The threat has not been observed exploiting a specific vulnerability but relies on social engineering and abuse of legitimate Windows functionality.
Mitigation Recommendations
No official patch or fix is available as this is a social engineering and living-off-the-land technique rather than a software vulnerability. Mitigation should focus on user awareness training to resist social engineering attempts, monitoring for unusual use of rundll32.exe and pcalua.exe, and proactive threat hunting for ordinal execution patterns and WebDAV connections over HTTPS. Endpoint detection and response (EDR) solutions should be tuned to detect these behaviors, although the most obfuscated variants may evade automated detection. Network controls could consider monitoring or restricting WebDAV traffic tunneled over HTTPS if feasible. Since no files are dropped, file-based detection is ineffective.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cyberproof.com/blog/clickfix-keeps-evolving-rundll32-ordinal-execution-over-webdav/"]
- Adversary
- null
- Pulse Id
- 6a696c957b6f57a0709333e4
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashf11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6 | — | |
hash5ef7bf4ed52be2a6d5ebbcf3076fba5f | MD5 of f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6 | |
hash9e03e983e26d4782a3fef0a6ebb47fdcd46974c9 | SHA1 of f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6 |
Domain
| Value | Description | Copy |
|---|---|---|
domaingentletouchchiropracticclinicauroracol.com | — | |
domainhcwjcope.poundbahis.com | — | |
domainuttepcheweaxtowxdj.gentletouchchiropracticclinicauroracol.com | — | |
domainvqrlwsmzu.webyek.com | — |
Threat ID: 6a69eceb9c2644c7f878acdf
Added to database: 07/29/2026, 12:07:07 UTC
Last enriched: 07/29/2026, 14:14:27 UTC
Last updated: 07/30/2026, 03:37:51 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.