SEO Poisoning Campaigns Targeting K-12
By: Matthew Otte
SEO Poisoning Campaigns Targeting K-12
By: Matthew Otte

SEO Poisoning — Targeting K-12
It is every security professional’s worst nightmare: You open your inbox to see a subject line “Potential Pre-Ransomware Notification” sent from a three-letter agency looking back at you. After verifying the sender’s credentials are legitimate, a flurry of overwhelming tasks begin to fill your mind while a ticking clock rapidly counts down. Verify the true positive, identify the scope, identify the source, and protect your organization.
Can you handle it all before your sensitive information ends up on a ransomware exploit site?
This nightmare scenario recently played out for one of our public education clients. A government agency had reached out to their security team to alert them that traffic originating from their network was seen communicating with a known Gootloader IP. Any individual who has had the displeasure of receiving this type of alert knows that you often have very little time to react before a ransomware event occurs. Fortunately for our client, the issue was solved long before reaching this point.
Recently, Soteria identified a malicious script delivered to one of our client’s endpoints via the download of a .zip file. The end user was enticed into downloading the malware via SEO poisoning. The file was titled “Correlative_conjection_subject_verb_agreement_73855.zip”, and contained javascript. Upon execution, the script created a copy of itself and began reaching out to C2 domains. Soteria’s MDR service detected and isolated the activity before any additional effects were observed.
A similar incident occurred a few weeks beforehand with many overlapping details. Again, SEO poisoning was leveraged to entice a public education victim to download malware. In this case, the malware was titled “Free-name-writing-worksheets-for-kindergarten.exe”. Upon execution, this malware called a malicious PowerShell command to establish C2. Soteria’s MDR service detected and isolated the malicious activity before any additional effects were observed.
Fortunately, there are several steps your organization’s information security team can take to limit your risk of being impacted by this technique. Security teams can prepare themselves and their user base with user awareness training. End users should be made aware of the types of tactics threat actors employ to fool unsuspecting victims into installing their malware.
First, executable files should only be downloaded from trustworthy sources. Additionally, end users should be trained to be aware of the file extension that they are downloading/clicking on, and be sure to confirm it matches what they would expect. Further, malicious script execution can potentially be halted by changing domain-wide file association settings for .js and .vbs scripts to a tool like notepad. This will modify the default function of scripts to open in notepad instead of executing when clicked on. Note: In rare cases, this modification may disable certain legitimate .js or .vbs scripts that require a user to click on them. We recommend appropriate testing within your environment before making this change.
The pattern apparent in this string of events indicates a targeting of K-12 victims for various malware campaigns. This is evident through the use of known lesson plans for K-12 staff. Soteria’s mission is to help achieve cybersecurity for all. In that mission, we hope to share this information to arm public schools with the knowledge to prepare for and avoid potential threats.
Blue Team Help — Techniques & IOCs
- T1059.001 — Powershell was used to retrieve, decode, and execute a payload from the registry
- T1059.007 — Javascript was used as the initial payload
- T1053.005 — Scheduled tasks were used as a persistence mechanism
- T1204.002 — The user unknowingly executes the initial payload disguised as a legitimate file
- T1055.001 — A malicious DLL was injected into the legitimate SearchIndexer process
- T1112 —A malicious DLL was encrypted and stored in the registry

Text IOCs for ease of use
Filenames & Hashes
- correlative conjunction subject verb agreement 32158.js
- Social Media Communications.js
- Free-name-writing-worksheets-for-kindergarten.exe
- e7642e0cab9a719e660abf4e271040d3ca7e21ecc08ad04f6d39fc057cd4e5fd
- 70f883f5e784900aee37c340e9cf179a037753c04f9c311b4274a230f9757bfd
- 4f349e005eb9cebef10044b3f4aa181ea75cf9c107fb0683931397b2ea06a86d
Registry Key
- HKCU:\Software\Classes\ib21ob3mzuu
C2 Domains
- soycantante[.]es
- tebasia[.]com
- xobin[.]com
- vetexpert[.]eu
- prcp[.]com[.]pe
- fischerbauleistungen[.]de
- legacy-wow[.]com
- perverttubepremium[.]com
- fmworldcup[.]com
- gutenberg.marketing-flash[.]de
- drumlinsecurity[.]com
IP Addresses
- 217.160.0.228
- 136.243.93.116
- 104.26.9.101
- 51.83.236.81
- 35.194.48.132
- 185.30.32.129
- 146.112.61.106
- 146.112.61.106
- 35.214.254.168
- 146.112.61.107
- 34.160.81.203
메타데이터
- post_id
- 0e013cefa5d5
- slug
- seo-poisoning-k-12-0e013cefa5d5
- url
- https://blog.soteria.io/seo-poisoning-k-12-0e013cefa5d5
- canonical_url
- https://blog.soteria.io/seo-poisoning-k-12-0e013cefa5d5
- author_url
- https://medium.com/@Soteria_Security
- status
- ok
- fetched_at
- 2026-08-26 03:09:49