Behind the Booking.com Scam: ClickFix and a Phishing-as-a-Service Operation
Executive Summary A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling.

“I Paid Twice”: Inside the Booking.com Phishing Infrastructure Powering ClickFix Malware
Executive Summary
A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling. What makes this campaign dangerous is not just the phishing lure, but the well-structured malicious service infrastructure behind it from redirect domains and scripted payload delivery to malware staging and command-and-control.
By mapping this infrastructure end-to-end, defenders gain visibility into how initial phishing clicks evolve into ClickFix malware execution and, ultimately, remote access and credential theft.
Threat Overview: From Phish to Full Compromise
The campaign begins with fraudulent Booking.com-themed messages sent to hotels and customers. These messages claim payment issues, booking confirmations, or required document reviews. Victims who click are silently redirected through a network of look-alike domains designed to evade detection and rotate quickly.
Once the victim interacts with the fake page, the attack transitions into the ClickFix delivery stage, where malicious scripts guide the user into executing a payload often disguised as a legitimate update or verification step.
This campaign demonstrates how modern phishing operations function as service-based ecosystems, not isolated attacks.
ClickFix Malware Technical Snapshot

| Attribute | Value |
|---|---|
| Malware Name | ClickFix |
| File Type | PE64 |
| Operating System | Windows (Vista+) AMD64 |
| Signature | Unknown |
| VirusTotal Score | 42 malicious detections |
| Language | Python |
| (Heuristic) Language | JavaScript |
| Compiler | Microsoft Visual C/C++ |
| Toolchain | Visual Studio 2022 |
| Packer | PyInstaller (modified) |
| Overlay | Large compressed binary overlay |
| Compression | ZLIB / Raw Deflate |
Primary Hash (SHA1):5c6da6ad7054e97ca9a2eeb0c79085c45bc5996e
What We Observed During Static Investigation

While investigating the ClickFix payload, PeStudio highlights several red flags consistent with malicious loaders:
Suspicious API Imports such as
CreateProcessW,WriteFile, andDeleteFileWsuggest execution, persistence preparation, and cleanup activity.High entropy overlays indicate payload hiding through compression and packing.
Unsigned PE with unknown signature, often associated with fast-moving malware campaigns.
Mixed scripting artifacts, aligning with Python-based loaders deploying JavaScript-assisted execution logic.
Anti-analysis indicators, including sandbox and virtual environment checks, to evade automated detection.
These findings align with ClickFix being a delivery and staging component, not just a standalone binary.
Malware Capabilities & Behavior Mapping

MITRE ATT&CK Highlights
Defense Evasion
Obfuscated Files or Information (T1027)
Virtualization/Sandbox Evasion (T1497.001)
Discovery
File and Directory Discovery (T1083)
Process Discovery (T1057)
System Information Discovery (T1082)
Execution
Command and Scripting Interpreter (T1059)
Shared Modules (T1129)
Notable Capabilities Identified
XOR-encoded data handling
ZLIB compression and decompression
Runtime API linking
File system enumeration and manipulation
Process creation (including suspended processes)
Environment variable inspection and modification
Together, these behaviors indicate
loader-style malware, designed to prepare the system for follow-on payloads such as
PureRAT.
Why Infrastructure Visibility Matters
This campaign succeeds because it distributes risk across dozens of domains, redirectors, payload hosts, and C2 endpoints. Blocking a single URL or hash is not enough.
By correlating:
phishing redirect paths
PowerShell payload endpoints
malware staging servers
command-and-control nodes
defenders can disrupt the entire attack chain, not just individual indicators.

Indicators of Compromise (IOCs)
Recommendation: Block these indicators at email gateways, web proxies, EDR, and SIEM platforms.
ClickFix Cluster – Initial Phishing Redirects
| Type | Indicator |
|---|---|
| URL | hxxps://headkickscountry[.]com/lz1y |
| URL | hxxps://activatecapagm[.]com/j8r3 |
| URL | hxxps://homelycareinc[.]com/po7r |
| URL | hxxps://byliljedahl[.]com/8anf |
| URL | hxxps://jamerimprovementsllc[.]com/ao9o |
| URL | hxxps://seedsuccesspath[.]com/6m8a |
| URL | hxxps://zenavuurwerkofficial[.]com/62is |
| URL | hxxps://brownsugarcheesecakebar[.]com/ajm4 |
| URL | hxxps://hareandhosta[.]com/95xh |
| URL | hxxps://customvanityco[.]com/izsb |
| URL | hxxps://byliljedahl[.]com/lv6q |
ClickFix PowerShell Payload Delivery
| Type | Indicator |
|---|---|
| URL | hxxps://ctrlcapaserc[.]com/bomla |
| URL | hxxps://bknqsercise[.]com/bomla |
| URL | hxxps://bkngssercise[.]com/bomla |
| URL | hxxps://bkngpropadm[.]com/bomla |
| URL | hxxps://cquopymaiqna[.]com/bomla |
| URL | hxxps://emprotel[.]net[.]bo/updserc[.]zip |
| URL | hxxps://cabinetifc[.]com/upseisser[.]zip |
Cluster Domains (Phishing Infrastructure)
| Type | Indicator |
|---|---|
| Domain | whooamisercisea[.]com |
| Domain | whooamisercise[.]com |
| Domain | aidaqosmaioa[.]com |
| Domain | bqknsieasrs[.]com |
| Domain | update-infos616[.]com |
| Domain | mccplogma[.]com |
| Domain | mccp-logistics[.]com |
| Domain | cquopymaiqna[.]com |
| Domain | contmasqueis[.]com |
| Domain | update-info1676[.]com |
| Domain | admin-extranet-reservationsinfos[.]com |
| Domain | ctrlcapaserc[.]com |
| Domain | bkngssercise[.]com |
| Domain | bknqsercise[.]com |
| Domain | bookingadmin-updateofmay2705[.]com |
| Domain | booking-reservationinfosid0251358[.]com |
PureRAT Staging & C2
| Type | Indicator |
|---|---|
| URL | hxxps://ctrlcapaserc[.]com/loggqibkng |
| URL | hxxps://bqknsieasrs[.]com/loggqibkng |
| IP:Port | 85.208.84[.]94:56001 |
| IP:Port | 77.83.207[.]106:56001 |
| Hash | 703355e8e93f30df19f7f7b8800bd623f1aee1f020c43a4a1e11e121c53b5dd1 |
| Hash | 5301f5a3fb8649edb0a5768661d197f872d40cfe7b8252d482827ea27077c1ec |
| Hash | 64838e0a3e2711b62c4f0d2db5a26396ac7964e31500dbb8e8b1049495b5d1f3 |
Phishing Targeting Hotel Customers
| Type | Indicator |
|---|---|
| URL | hxxps://confirmation887-booking[.]com/17149438 |
| URL | hxxps://verifyguest02667-booking[.]com/17149438 |
| URL | hxxps://guest03442-booking[.]com/17149438 |
| URL | hxxps://confirmation8324-booking[.]com/17149438 |
| URL | hxxps://cardverify0006-booking[.]com/37858999 |
| URL | hxxps://verifycard45625-expedia[.]com/67764524 |
Final Thoughts
The “I Paid Twice” campaign highlights how phishing has evolved into modular, resilient service infrastructures that blend social engineering with malware delivery and remote access tooling.
Organizations in the hospitality sector and those protecting them must move beyond surface-level detection and focus on full attack-path visibility, correlating phishing, payload delivery, and command-and-control activity.
Blocking infrastructure, not just files, is now a defensive necessity.



