s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

OTX-6ab68af3aecfcfc39b2824d8 info

📛 Threat Title

The Psychedelic Stealer: When a CAPTCHA Becomes an Installer

Category: psychedelic Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psychedelic.” Pulse contains 11 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (11)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2026-84869

IOC database

Type
cve
Value
CVE-2026-84869
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-76461

IOC database

Type
cve
Value
CVE-2026-76461
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Cisco Secure Email Gateway SQL Injection Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-85102

IOC database

Type
cve
Value
CVE-2026-85102
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Check Point Multiple Products Improper Certificate Validation Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-85103

IOC database

Type
cve
Value
CVE-2026-85103
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 107.175.82.242 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/107.175.82.242

IOC database

Type
ipv4
Value
107.175.82.242
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
CC=US ASN=AS36352 colocrossing

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/107.175.82.242

ipv4 193.178.159.128 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/193.178.159.128

IOC database

Type
ipv4
Value
193.178.159.128
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
CC=RU ASN=AS20499 ip communications ltd.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/193.178.159.128

hash_sha256 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 VT 50 / 75

IOC database

Type
hash_sha256
Value
06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.MalwareX-gen.C5945701
Alibaba malicious TrojanSpy:Win32/Stealer.237b76fe
alibabacloud malicious Trojan[spy]:Win/Agent_AGen.QCB
ALYac malicious Trojan.GenericKD.81432754
Antiy-AVL malicious Trojan/Win32.Agent
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4DA90B2
Avast malicious Win64:MalwareX-gen [Misc]
AVG malicious Win64:MalwareX-gen [Misc]
Avira malicious TR/W64.Agent
BitDefender malicious Trojan.GenericKD.81432754
Bkav malicious W32.Malware.83F0A93B
CrowdStrike malicious win/malicious_confidence_70% (D)
CTX malicious exe.trojan.stealer
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DrWeb malicious Trojan.Siggen34.11984
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.81432754 (B)
ESET-NOD32 malicious Win64/Spy.Agent.BDK trojan
F-Secure malicious Trojan.TR/W64.Agent
Fortinet malicious W64/Agent_AGen.QUT!tr
GData malicious Trojan.GenericKD.81432754
Google malicious Detected
K7AntiVirus malicious Spyware ( 006e680a1 )
K7GW malicious Spyware ( 006e680a1 )
Kaspersky malicious Trojan-Spy.Win32.Stealer.fuwo
Kingsoft malicious Win32.Trojan-Spy.Stealer.fuwo
Lionic malicious Trojan.Win32.Stealer.12!c
Malwarebytes malicious Spyware.Stealer
MaxSecure malicious Trojan.Malware.402022142.susgen
McAfeeD malicious ti!06F434695F93
Microsoft malicious Trojan:Win64/PsychedelicStealer.DA!MTB
MicroWorld-eScan malicious Trojan.GenericKD.81432754
Paloalto malicious generic.ml
Rising malicious Spyware.Agent!8.C6 (CLOUD)
Sangfor malicious Spyware.Win32.Agent.V8r1
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious BehavesLike.Win64.Injector.dh
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Trojan-Spy/W64.InfoStealer.281600
Tencent malicious Malware.Win32.Gencirc.14b55e88
TrellixENS malicious Artemis!AE5450F32BCB
TrendMicro malicious Trojan.Win32.WACATAC.USBLIF26
TrendMicro-HouseCall malicious Trojan.Win32.WACATAC.USBLIF26
Varist malicious W64/ABTrojan.ZEMO-3649
VBA32 malicious Trojan.Wacatac
VIPRE malicious Trojan.GenericKD.81432754
Yandex malicious TrojanSpy.Agent!W/X3fLYloAA

Details From VirusTotal

Basic Properties
MD5ae5450f32bcb533c5b592c77a7861553
SHA-185e01bdb2aee0217932e108535691c898b138a80
SHA-25606f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
VHash0250b76d156575551c0d10c3z32z383d5z5045z23z1fz
SSDEEP6144:fheWYL+ZPJIYjK9GZLBpdPGq1Kq0CGpNMm:fHPZCYjK9GZdPGqd+NM
TLSHT132545C57E25364ECC167D2388697A732B932786201747E6B3A1CC6727F21E60A73EF14
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
File size275.0 KB
History
Creation date2026-09-12 01:44 UTC
First seen on VirusTotal2026-09-12 20:42 UTC
Last submission2026-09-25 14:47 UTC
Last analysis2026-09-25 13:54 UTC
Last modified on VirusTotal2026-09-25 23:26 UTC
Known Names
  • 29pnm.exe
  • 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90.exe
  • psychedeliclove.exe
  • 9hfqs8p.exe
hash_sha256 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 VT 31 / 75

IOC database

Type
hash_sha256
Value
38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 31 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/GenKryptik_AGen.FUX
ALYac malicious Trojan.GenericKD.81435355
Arcabit malicious Trojan.Generic.D4DA9ADB
Avast malicious Win64:MalwareX-gen [Cryp]
AVG malicious Win64:MalwareX-gen [Cryp]
Avira malicious TR/W64.MalwareX
BitDefender malicious Trojan.GenericKD.81435355
CTX malicious msi.trojan.agen
Cynet malicious Malicious (score: 99)
DrWeb malicious Trojan.DownLoader50.23749
Emsisoft malicious Trojan.GenericKD.81435355 (B)
ESET-NOD32 malicious Win64/GenKryptik_AGen.FGO trojan
F-Secure malicious Trojan.TR/W64.MalwareX
Fortinet malicious W64/GenKryptik_AGen.FGO!tr
GData malicious Trojan.GenericKD.81435355
Google malicious Detected
K7AntiVirus malicious Trojan ( 006e6d651 )
K7GW malicious Trojan ( 006e6d651 )
Kaspersky malicious Backdoor.MSIL.Agent.afty
Lionic malicious Trojan.Win32.Generic.4!c
Microsoft malicious Trojan:Win32/Malgent
Rising malicious Trojan.Kryptik!8.8 (CLOUD)
Sangfor malicious Trojan.Win64.Kryptik.V20j
SentinelOne malicious Static AI - Suspicious MSI
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
Tencent malicious Malware.Win32.Gencirc.14b56fed
TrellixENS malicious Artemis!348CABE85C8B
TrendMicro malicious Trojan.Win64.GENKRYPTIKAGEN.USBLIG26
Varist malicious W64/ABRisk.LBIJ-5183
VIPRE malicious Trojan.GenericKD.81435355

Details From VirusTotal

Basic Properties
MD51f250eb486571d99bc1e4d760e37a554
SHA-194a102fb67c4d65a83c64e9d57a79fae7ad63d92
SHA-25638e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878
VHash30b37eee994065929a36506bc6d40e4c
SSDEEP24576:doT4PLqXxmX1bUdvuC1lZ18B77eOoNUsGP9e6yq6/2s:doT4PLqhmFYukx8t7e+lpa
TLSHT1FC45232635496277C1A3077A134FD3D897368C0843B341672096B5DD6AB5EA0EEF3AEC
File typeWindows Installer
File type tagmsi
File extensionmsi
MagicComposite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Title: Installation Database, Subject: Vertification, Author: Internal Software, Revision Number: {BF423059-8CC9-4707-924A-11A8113B9D3B}, Name of Creating Application: Python MSI Library, Number of Words: 10, Number of Pages: 500, Template: Intel;1033
File size1.1 MB
History
First seen on VirusTotal2026-09-14 12:02 UTC
Last submission2026-09-14 23:35 UTC
Last analysis2026-09-25 13:54 UTC
Last modified on VirusTotal2026-09-25 15:56 UTC
Known Names
  • elita.msi
url https://uasputnik.com/elita.msi VT 21 / 92 UrlVoid 5 / 36

IOC database

Type
url
Value
https://uasputnik.com/elita.msi
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 21 of 92 VirusTotal vendors

VendorVerdictDetection
BitDefender malicious phishing
Certego malicious phishing
Cluster25 malicious malicious
CRDF malicious malicious
CyRadar malicious malicious
Dr.Web malicious malicious
Emsisoft malicious malware
ESET malicious malware
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious phishing
Gridinsoft malicious phishing
Lionic malicious malicious
Rising malicious malicious
Seclookup malicious malicious
SOCRadar malicious phishing
Sophos malicious malware
Viettel Threat Intelligence malicious malicious
VIPRE malicious malware
Webroot malicious malicious
alphaMountain.ai suspicious suspicious

Details From VirusTotal

Basic Properties
TLDcom
Final URLhttps://uasputnik.com/elita.msi
Last HTTP status200
History
First seen on VirusTotal2026-09-14 12:35 UTC
Last submission2026-09-25 10:58 UTC
Last analysis2026-09-25 10:58 UTC
Last modified on VirusTotal2026-09-25 15:53 UTC
url https://uasputnik.com/sputnik.html VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly91YXNwdXRuaWsuY29tL3NwdXRuaWsuaHRtbA

IOC database

Type
url
Value
https://uasputnik.com/sputnik.html
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly91YXNwdXRuaWsuY29tL3NwdXRuaWsuaHRtbA

url http://107.175.82.242:9000/wilow/psychedeliclove.exe VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzEwNy4xNzUuODIuMjQyOjkwMDAvd2lsb3cvcHN5Y2hlZGVsaWNsb3ZlLmV4ZQ

IOC database

Type
url
Value
http://107.175.82.242:9000/wilow/psychedeliclove.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzEwNy4xNzUuODIuMjQyOjkwMDAvd2lsb3cvcHN5Y2hlZGVsaWNsb3ZlLmV4ZQ

References (2)

  • reference AlienVaulkt OTX
  • OTX pulse AlienVaulkt OTX

    Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psych

Remediations (8)

  • web:www.shengzheweiwang.com

    Arctic Wolf Labs is tracking a fake Cloudflare CAPTCHA campaign delivering Psychedelic Stealer , malware which steals browser passwords, account tokens, and wallet data.

  • web:daily.dev

    Questions this post answers What is Psychedelic Stealer and what data does it steal? Psychedelic Stealer is a previously unidentified 64-bit Windows infostealer (SHA-256: 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90) delivered via a fake Cloudflare CAPTCHA ClickFix campaign.

  • web:github.com

    Psychedelic Stealer is a 64-bit Windows executable that profiles the infected host — collecting OS details, hardware configuration, installed browsers, and antivirus products — before exfiltrating data. It specifically targets Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex for credential and token theft.

  • web:securityaffairs.com

    Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials.

  • web:securityarsenal.com

    Compromised Ukrainian business sites are serving fake Cloudflare verification pages that trick users into pasting msiexec commands, silently installing the new Psychedelic info- stealer .

  • web:socprime.com

    Summary Arctic Wolf Labs is tracking a campaign that uses fake Cloudflare CAPTCHA lures injected into compromised Ukrainian business websites. The ClickFix-style attack convinces users to execute an MSI package that installs Psychedelic Stealer , an infostealer designed to collect browser credentials, account tokens, and cryptocurrency wallet data. The malware also supports persistent remote ...

  • web:www.techzine.eu

    Arctic Wolf discovers Psychedelic Stealer : hacked Ukrainian sites display a fake CAPTCHA that installs an info- stealer via msiexec.

  • web:www.threatops.tech

    When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag " Psychedelic ."

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…