Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV

0
Medium
Published: 07/29/2026 (07/29/2026, 02:59:33 UTC)
Source: AlienVault OTX General

Description

A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 14:14:27 UTC

Technical Analysis

The ClickFix campaign variant uses social engineering to induce victims to run commands via the Windows Run dialog, leveraging rundll32.exe to execute remote payloads over WebDAV tunneled through HTTPS port 443. Payloads are invoked by ordinal export #1, not by named functions, complicating detection. The campaign features evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade automated detection. It also abuses trusted Windows binaries such as pcalua.exe to disrupt process lineage tracking. No files are written to disk during the attack, making traditional file-based detection ineffective. The campaign has successfully exfiltrated browser credentials and sensitive documents. The most advanced variants have bypassed automated EDR detection and were identified only through focused threat hunting on ordinal execution techniques.

Potential Impact

The campaign enables attackers to execute remote payloads without dropping files to disk, evading many traditional detection mechanisms. It results in credential theft and exfiltration of sensitive documents (approximately 13MB). The use of trusted Windows binaries and obfuscation techniques complicates detection and forensic analysis. The threat has not been observed exploiting a specific vulnerability but relies on social engineering and abuse of legitimate Windows functionality.

Mitigation Recommendations

No official patch or fix is available as this is a social engineering and living-off-the-land technique rather than a software vulnerability. Mitigation should focus on user awareness training to resist social engineering attempts, monitoring for unusual use of rundll32.exe and pcalua.exe, and proactive threat hunting for ordinal execution patterns and WebDAV connections over HTTPS. Endpoint detection and response (EDR) solutions should be tuned to detect these behaviors, although the most obfuscated variants may evade automated detection. Network controls could consider monitoring or restricting WebDAV traffic tunneled over HTTPS if feasible. Since no files are dropped, file-based detection is ineffective.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cyberproof.com/blog/clickfix-keeps-evolving-rundll32-ordinal-execution-over-webdav/"]
Adversary
null
Pulse Id
6a696c957b6f57a0709333e4
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6
hash5ef7bf4ed52be2a6d5ebbcf3076fba5f
MD5 of f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6
hash9e03e983e26d4782a3fef0a6ebb47fdcd46974c9
SHA1 of f11057ab58bef936d98ba189829c64260a6a540cdaa046f93613138e820c98c6

Domain

ValueDescriptionCopy
domaingentletouchchiropracticclinicauroracol.com
domainhcwjcope.poundbahis.com
domainuttepcheweaxtowxdj.gentletouchchiropracticclinicauroracol.com
domainvqrlwsmzu.webyek.com

Threat ID: 6a69eceb9c2644c7f878acdf

Added to database: 07/29/2026, 12:07:07 UTC

Last enriched: 07/29/2026, 14:14:27 UTC

Last updated: 07/30/2026, 03:37:51 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses