Authored By Sakshi Jaiswal
McAfee Labs recently observed a surge in phishing campaigns that use fake viral video links to trick users into downloading malware. The attack relies on social engineering, redirecting victims through multiple malicious websites before delivering the payload. Users are enticed with promises of exclusive content, ultimately leading them to fraudulent pages and deceptive download links.
Figure 1: Geo Heatmap showing McAfee customer encounters over the past 3 weeks.
1. Upon executing the PDF file, the displayed page appears to be part of a phishing scam leveraging clickbait about a “viral video” to lure users into clicking suspicious links. The document contains blue hyperlinked text labeled as “Watch ➤ Click Here To Link (Full Viral Video Link)” and a deceptive video player graphic, giving the illusion of a playable video.
Figure 2: PDF Image
2. The user clicks on “Watch ➤ Click Here To Link (Full Viral Video Link)“, which redirects them to a webpage ( displaying fake “viral video leaked” content, excessive ads, and fake notifications to lure users. It promotes adult content, gambling, and misleading download buttons, which are common indicators of phishing or malware traps.
Figure 3: Redirected Webpage
3. This further redirects to malicious URL “hxxps[:]//”
Figure 4: Redirected Webpage2
4. And then redirected to below URL: “hxxps[:]//” which presents a password-protected download link hosted on, requiring the user to manually copy and paste the URL.
Figure 5: Redirected Webpage with download link
5. Upon checking the URL, it displays a loading screen while preparing the malicious file for download and then shows a downloadable file named with a size of 26.7 MB.
Figure 6: Screenshot of a ZIP file download from MEGA
6. Download is completed and stored in downloads folder
Figure 7: Zip file downloaded
7. A ZIP archive (, 26.7 MB) file contains a password protected .7z file with .png file containing the password.
Figure 8: Files inside ZIP archive
8. The extracted .7z archive contains setup.msi, which is the actual malware payload.
Figure 9: setup.msi file
Upon execution of setup.msi, the malware:
1. Displays a CAPTCHA image to deceive users. upon clicking “OK,” it begins dropping files in the %Roaming% directory.
Figure 10: Screenshot of CAPTCHA image
2. Drops files into the %Roaming% directory.
Figure 11: Dropped multiple files in %Roaming%
Process Execution & Command Lines
Process Tree
Figure 12: Process Tree
Command Lines
- C:\Windows\system32\msiexec.exe /V
- C:\Windows\syswow64\MsiExec.exe -Embedding B8B3D9D8EE75B04B6E518D4C8B1DA31A
- “C:\Users\****\AppData\Roaming\Toiap Corp Solus\Kowi SApp\UnRar.exe” x -p156427613t -o+ “C:\Users\****\AppData\Roaming\Toiap Corp Solus\Kowi SApp\iwhgjds.rar” “C:\Users\****\AppData\Roaming\Toiap Corp Solus\Kowi SApp\”
- \??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
- “C:\Users\****\AppData\Roaming\Toiap Corp Solus\Kowi SApp\obs-ffmpeg-mux.exe”
- \??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
- C:\Windows\SysWOW64\explorer.exe explorer.exe
- \??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
- C:\Windows\system32\WerFault.exe -u -p 3064 -s 316
- “C:\Users\****\AppData\Roaming\Toiap Corp Solus\Kowi SApp\createdump.exe”
- \??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
- C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc
- C:\Windows\System32\svchost.exe -k WerSvcGroup
- C:\Windows\system32\WerFault.exe -pss -s 432 -p 3064 -ip 3064
Detection & Coverage
McAfee intercepts and blocks this infection chain at multiple stages.
URL blocking of the fake video pages.
Figure 13: McAfee Blocking URL
Figure 14: McAfee PDF file Detection
Conclusion and Recommendations
This campaign highlights how cybercriminals exploit social engineering tactics and clickbait content to distribute malware. Users should remain cautious when encountering suspicious video links. To stay protected against phishing attacks and malware infections, McAfee recommends:
- Avoid clicking on suspicious links in emails, social media posts, or messages that promise exclusive or leaked content.
- Verify file sources before downloading by checking domain legitimacy and scanning files with McAfee security solutions.
- Enable real-time security updates to ensure endpoint protection remains updated against the latest threats.
- Utilize McAfee Web Protection to block access to known phishing and malware-hosting websites.
Indicators of Compromise (IoCs)
Sha256 Hash List
- 00001c98e08fa4d7f4924bd1c375149104bd4f1981cef604755d34ca225f2ce1
- 000e75287631a93264d11fc2b773c61992664277386f45fa19897a095e6a7c81
- 52c606609dab25cdd43f831140d7f296d89f9f979e00918f712018e8cc1b6750
- 00539e997eb6ae5f6f7cb050c3486a6dfb901b1268c13bdfeeec5b776bf81c1e
- 0047d7a61fd9279c9fba9a604ed892e4ec9d732b10c6562aab1938486a538b7d
Redirecting Websites
- hxxps[:]//
- hxxps[:]//
- hxxps[:]//
- hxxps[:]//
- hxxps[:]//
- hxxps[:]//
- hxxps[:]//

Introducing McAfee+
Identity theft protection and privacy for your digital life