typeanalysisfamilyclickfixconfidencelowcreated2026-08-16updated2026-08-16
SHA-256: d8f0227793cbb22d7d2ed3522ab006b9959c348db25878325dc82b7cfecdbfb1

d8f02277 — clickfix (preliminary)

PE32+ x86-64 GUI executable, 13.96 MB. PyInstaller 6.x CArchive with PyArmor runtime and Python 3.13 embedded runtime. Static-only; CAPE skipped (no Windows guest).

Build / RE

Toolchain. PyInstaller 6.x one-file mode, Python 3.13 (python313.dll in TOC), PyArmor runtime (pyarmor_runtime_000000\pyarmor_runtime.pyd) ^[strings.txt:23167]. Standard-library dependencies include psutil (system/process enumeration) and hashlib (likely PyArmor integrity check). No custom native compilation artifacts; pure-Python payload.

Packing. Outer PE is the PyInstaller bootloader (CFFI archive appended past PE sections) ^[concepts/pyinstaller-bootloader.md]. Overlay begins at 0x49000 and spans 13,663,974 bytes (97.9% of file) ^[rabin2-info.txt]. CArchive cookie at file offset 0xD50E8E: magic MEI\x0c\x0b\x0a\x0b\x0e, archive_len 0xD07EE6, toc_offset 0xD0786E, toc_len 0x620, pyver=313 ^[manual]. TOC lists 27+ entries including mstruct, pyimod0{1-4}_*, spyiboot01_bootstrap, data_p002\*, pyarmor_runtime_000000\pyarmor_runtime.pyd, and python313.dll.

Obfuscation. PyArmor runtime obfuscation for the embedded Python bytecode ^[strings.txt:23113]. No additional packer (UPX, Themida) detected. floss decoded-string pass produced only argument-parsing boilerplate ^[floss.txt:1]; PyArmor's string encryption defeated FLOSS.

Anti-analysis. No VM-detection, anti-debug, or sandbox-evasion strings observed in the bootloader. PyArmor's C-extension runtime itself provides anti-tamper (checksum verification, obfuscated control flow) but no environment gates were visible statically.

Embedded resources. TOC entry data_p002 subtree contains: 002.xml, 002_b.js, 002_d.js, 002_n.js, 002a.txt, 002w.txt, pack.js, uusd.exe ^[manual]. These filenames (XML manifest, JavaScript modules, packed extension, secondary executable) are consistent with a browser-extension deployment package. Direct carving was blocked by TOC-field ambiguity; payload content remains uninspected.

Deploy / ATT&CK

Static-only inference. No CAPE detonation available. All TTPs below are inferred from filenames, tooling, and OpenCTI campaign context.

Social engineering. The OpenCTI label clickfix and co-label efimer align with the ClickFix / ClearFake campaign: compromised websites display a fake CAPTCHA ("I'm not a robot") that copies a PowerShell payload to the clipboard and instructs the victim to paste it into Win+R ^[triage.json]. This sample is the stage-2 payload delivered by that PowerShell.

Browser extension sideload. The data_p002\*.js + *.xml + pack.js filenames strongly suggest a Chromium-extension installation package. Likely technique: registry policy hijack (ExtensionInstallForcelist) or UI-automation fallback to force-install the extension ^[techniques/browser-extension-sideload-crx3.md]. Once installed, the extension can read all tab data, inject scripts, intercept credentials, and maintain persistence independent of the PE process.

Secondary payload. uusd.exe (inside data_p002) is likely a compiled infostealer or RAT that the main Python script drops and executes. The name uusd.exe does not match any known legitimate binary; it is probably randomized per build.

Persistence. PyInstaller one-file mode drops to %TEMP%\_MEI<XXXX> at runtime and executes from there. The extension sideload (if confirmed) provides registry-based persistence via Chrome enterprise policies. No schtasks, Run key, or WMI strings were observed statically.

C2 / Comms. No hardcoded URLs, IPs, webhooks, or domain names in plaintext strings. PyArmor encrypts all strings at rest. C2 is likely configured in the obfuscated Python payload or the uusd.exe secondary binary.

Attribution. Preliminary family: clickfix (OpenCTI label). The efimer co-label may indicate a specific sub-campaign or builder variant. No code-reuse overlaps with other families in the corpus. Medium-confidence attribution based on campaign tooling and OpenCTI consensus; low-confidence on exact payload behavior because the stage-2 files were not extracted.

Confidence

  • Family: low — OpenCTI label is the only anchor; no payload extraction to confirm behavior.
  • Toolchain: high — PyInstaller + PyArmor + Python 3.13 are unambiguous.
  • Browser-extension hypothesis: medium — filenames are strongly indicative but content was not verified.

References

  • file.txt, rabin2-info.txt, strings.txt, binwalk.txt, triage.json — static artifacts in canonical analysis directory.
  • OpenCTI labels: clickfix, efimer, exe, malware-bazaar ^[triage.json].