OTX-6ab68af3aecfcfc39b2824d8
info
📛 Threat Title
The Psychedelic Stealer: When a CAPTCHA Becomes an Installer
Description
Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psychedelic.” Pulse contains 11 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (11)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2026-84869
IOC database
- Type
- cve
- Value
CVE-2026-84869- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-76461
IOC database
- Type
- cve
- Value
CVE-2026-76461- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Cisco Secure Email Gateway SQL Injection Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-85102
IOC database
- Type
- cve
- Value
CVE-2026-85102- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Check Point Multiple Products Improper Certificate Validation Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-85103
IOC database
- Type
- cve
- Value
CVE-2026-85103- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
107.175.82.242
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/107.175.82.242
IOC database
- Type
- ipv4
- Value
107.175.82.242- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- CC=US ASN=AS36352 colocrossing
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/107.175.82.242
ipv4
193.178.159.128
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/193.178.159.128
IOC database
- Type
- ipv4
- Value
193.178.159.128- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- CC=RU ASN=AS20499 ip communications ltd.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/193.178.159.128
hash_sha256
06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
VT 50 / 75
IOC database
- Type
- hash_sha256
- Value
06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.MalwareX-gen.C5945701 |
| Alibaba | malicious | TrojanSpy:Win32/Stealer.237b76fe |
| alibabacloud | malicious | Trojan[spy]:Win/Agent_AGen.QCB |
| ALYac | malicious | Trojan.GenericKD.81432754 |
| Antiy-AVL | malicious | Trojan/Win32.Agent |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4DA90B2 |
| Avast | malicious | Win64:MalwareX-gen [Misc] |
| AVG | malicious | Win64:MalwareX-gen [Misc] |
| Avira | malicious | TR/W64.Agent |
| BitDefender | malicious | Trojan.GenericKD.81432754 |
| Bkav | malicious | W32.Malware.83F0A93B |
| CrowdStrike | malicious | win/malicious_confidence_70% (D) |
| CTX | malicious | exe.trojan.stealer |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DrWeb | malicious | Trojan.Siggen34.11984 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.81432754 (B) |
| ESET-NOD32 | malicious | Win64/Spy.Agent.BDK trojan |
| F-Secure | malicious | Trojan.TR/W64.Agent |
| Fortinet | malicious | W64/Agent_AGen.QUT!tr |
| GData | malicious | Trojan.GenericKD.81432754 |
| malicious | Detected |
|
| K7AntiVirus | malicious | Spyware ( 006e680a1 ) |
| K7GW | malicious | Spyware ( 006e680a1 ) |
| Kaspersky | malicious | Trojan-Spy.Win32.Stealer.fuwo |
| Kingsoft | malicious | Win32.Trojan-Spy.Stealer.fuwo |
| Lionic | malicious | Trojan.Win32.Stealer.12!c |
| Malwarebytes | malicious | Spyware.Stealer |
| MaxSecure | malicious | Trojan.Malware.402022142.susgen |
| McAfeeD | malicious | ti!06F434695F93 |
| Microsoft | malicious | Trojan:Win64/PsychedelicStealer.DA!MTB |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81432754 |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Spyware.Agent!8.C6 (CLOUD) |
| Sangfor | malicious | Spyware.Win32.Agent.V8r1 |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Skyhigh | malicious | BehavesLike.Win64.Injector.dh |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Trojan-Spy/W64.InfoStealer.281600 |
| Tencent | malicious | Malware.Win32.Gencirc.14b55e88 |
| TrellixENS | malicious | Artemis!AE5450F32BCB |
| TrendMicro | malicious | Trojan.Win32.WACATAC.USBLIF26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.WACATAC.USBLIF26 |
| Varist | malicious | W64/ABTrojan.ZEMO-3649 |
| VBA32 | malicious | Trojan.Wacatac |
| VIPRE | malicious | Trojan.GenericKD.81432754 |
| Yandex | malicious | TrojanSpy.Agent!W/X3fLYloAA |
Details From VirusTotal
Basic Properties
| MD5 | ae5450f32bcb533c5b592c77a7861553 |
| SHA-1 | 85e01bdb2aee0217932e108535691c898b138a80 |
| SHA-256 | 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 |
| VHash | 0250b76d156575551c0d10c3z32z383d5z5045z23z1fz |
| SSDEEP | 6144:fheWYL+ZPJIYjK9GZLBpdPGq1Kq0CGpNMm:fHPZCYjK9GZdPGqd+NM |
| TLSH | T132545C57E25364ECC167D2388697A732B932786201747E6B3A1CC6727F21E60A73EF14 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows |
| File size | 275.0 KB |
History
| Creation date | 2026-09-12 01:44 UTC |
| First seen on VirusTotal | 2026-09-12 20:42 UTC |
| Last submission | 2026-09-25 14:47 UTC |
| Last analysis | 2026-09-25 13:54 UTC |
| Last modified on VirusTotal | 2026-09-25 23:26 UTC |
Known Names
29pnm.exe06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90.exepsychedeliclove.exe9hfqs8p.exe
hash_sha256
38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878
VT 31 / 75
IOC database
- Type
- hash_sha256
- Value
38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 31 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/GenKryptik_AGen.FUX |
| ALYac | malicious | Trojan.GenericKD.81435355 |
| Arcabit | malicious | Trojan.Generic.D4DA9ADB |
| Avast | malicious | Win64:MalwareX-gen [Cryp] |
| AVG | malicious | Win64:MalwareX-gen [Cryp] |
| Avira | malicious | TR/W64.MalwareX |
| BitDefender | malicious | Trojan.GenericKD.81435355 |
| CTX | malicious | msi.trojan.agen |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Trojan.DownLoader50.23749 |
| Emsisoft | malicious | Trojan.GenericKD.81435355 (B) |
| ESET-NOD32 | malicious | Win64/GenKryptik_AGen.FGO trojan |
| F-Secure | malicious | Trojan.TR/W64.MalwareX |
| Fortinet | malicious | W64/GenKryptik_AGen.FGO!tr |
| GData | malicious | Trojan.GenericKD.81435355 |
| malicious | Detected |
|
| K7AntiVirus | malicious | Trojan ( 006e6d651 ) |
| K7GW | malicious | Trojan ( 006e6d651 ) |
| Kaspersky | malicious | Backdoor.MSIL.Agent.afty |
| Lionic | malicious | Trojan.Win32.Generic.4!c |
| Microsoft | malicious | Trojan:Win32/Malgent |
| Rising | malicious | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | malicious | Trojan.Win64.Kryptik.V20j |
| SentinelOne | malicious | Static AI - Suspicious MSI |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Malware.Win32.Gencirc.14b56fed |
| TrellixENS | malicious | Artemis!348CABE85C8B |
| TrendMicro | malicious | Trojan.Win64.GENKRYPTIKAGEN.USBLIG26 |
| Varist | malicious | W64/ABRisk.LBIJ-5183 |
| VIPRE | malicious | Trojan.GenericKD.81435355 |
Details From VirusTotal
Basic Properties
| MD5 | 1f250eb486571d99bc1e4d760e37a554 |
| SHA-1 | 94a102fb67c4d65a83c64e9d57a79fae7ad63d92 |
| SHA-256 | 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 |
| VHash | 30b37eee994065929a36506bc6d40e4c |
| SSDEEP | 24576:doT4PLqXxmX1bUdvuC1lZ18B77eOoNUsGP9e6yq6/2s:doT4PLqhmFYukx8t7e+lpa |
| TLSH | T1FC45232635496277C1A3077A134FD3D897368C0843B341672096B5DD6AB5EA0EEF3AEC |
| File type | Windows Installer |
| File type tag | msi |
| File extension | msi |
| Magic | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Title: Installation Database, Subject: Vertification, Author: Internal Software, Revision Number: {BF423059-8CC9-4707-924A-11A8113B9D3B}, Name of Creating Application: Python MSI Library, Number of Words: 10, Number of Pages: 500, Template: Intel;1033 |
| File size | 1.1 MB |
History
| First seen on VirusTotal | 2026-09-14 12:02 UTC |
| Last submission | 2026-09-14 23:35 UTC |
| Last analysis | 2026-09-25 13:54 UTC |
| Last modified on VirusTotal | 2026-09-25 15:56 UTC |
Known Names
elita.msi
url
https://uasputnik.com/elita.msi
VT 21 / 92
UrlVoid 5 / 36
IOC database
- Type
- url
- Value
https://uasputnik.com/elita.msi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 21 of 92 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| BitDefender | malicious | phishing |
| Certego | malicious | phishing |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Emsisoft | malicious | malware |
| ESET | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| Gridinsoft | malicious | phishing |
| Lionic | malicious | malicious |
| Rising | malicious | malicious |
| Seclookup | malicious | malicious |
| SOCRadar | malicious | phishing |
| Sophos | malicious | malware |
| Viettel Threat Intelligence | malicious | malicious |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | com |
| Final URL | https://uasputnik.com/elita.msi |
| Last HTTP status | 200 |
History
| First seen on VirusTotal | 2026-09-14 12:35 UTC |
| Last submission | 2026-09-25 10:58 UTC |
| Last analysis | 2026-09-25 10:58 UTC |
| Last modified on VirusTotal | 2026-09-25 15:53 UTC |
url
https://uasputnik.com/sputnik.html
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly91YXNwdXRuaWsuY29tL3NwdXRuaWsuaHRtbA
IOC database
- Type
- url
- Value
https://uasputnik.com/sputnik.html- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly91YXNwdXRuaWsuY29tL3NwdXRuaWsuaHRtbA
url
http://107.175.82.242:9000/wilow/psychedeliclove.exe
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzEwNy4xNzUuODIuMjQyOjkwMDAvd2lsb3cvcHN5Y2hlZGVsaWNsb3ZlLmV4ZQ
IOC database
- Type
- url
- Value
http://107.175.82.242:9000/wilow/psychedeliclove.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzEwNy4xNzUuODIuMjQyOjkwMDAvd2lsb3cvcHN5Y2hlZGVsaWNsb3ZlLmV4ZQ
References (2)
- reference AlienVaulkt OTX
-
OTX pulse
AlienVaulkt OTX
Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psych
Remediations (8)
-
web:www.shengzheweiwang.com
Arctic Wolf Labs is tracking a fake Cloudflare CAPTCHA campaign delivering Psychedelic Stealer , malware which steals browser passwords, account tokens, and wallet data.
-
web:daily.dev
Questions this post answers What is Psychedelic Stealer and what data does it steal? Psychedelic Stealer is a previously unidentified 64-bit Windows infostealer (SHA-256: 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90) delivered via a fake Cloudflare CAPTCHA ClickFix campaign.
-
web:github.com
Psychedelic Stealer is a 64-bit Windows executable that profiles the infected host — collecting OS details, hardware configuration, installed browsers, and antivirus products — before exfiltrating data. It specifically targets Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex for credential and token theft.
-
web:securityaffairs.com
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials.
-
web:securityarsenal.com
Compromised Ukrainian business sites are serving fake Cloudflare verification pages that trick users into pasting msiexec commands, silently installing the new Psychedelic info- stealer .
-
web:socprime.com
Summary Arctic Wolf Labs is tracking a campaign that uses fake Cloudflare CAPTCHA lures injected into compromised Ukrainian business websites. The ClickFix-style attack convinces users to execute an MSI package that installs Psychedelic Stealer , an infostealer designed to collect browser credentials, account tokens, and cryptocurrency wallet data. The malware also supports persistent remote ...
-
web:www.techzine.eu
Arctic Wolf discovers Psychedelic Stealer : hacked Ukrainian sites display a fake CAPTCHA that installs an info- stealer via msiexec.
-
web:www.threatops.tech
When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag " Psychedelic ."
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.