THREAT OPS › Threat News › Tracking PavinLoader across ClickFix and fake download campaigns
Tracking PavinLoader across ClickFix and fake download campaigns
<p class="wp-block-paragraph">In our <a href="https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding" rel="noreferrer noopener" target="_blank">previous analysis</a> of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain.</p>
<p class="wp-block-paragraph">Further threat hun
MITRE ATT&CK techniques
Indicators of compromise
- bdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14csha256
- e3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9sha256
- a4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717bsha256
- bf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376esha256
- 54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91sha256
- c1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adbsha256
- 001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09sha256
- 2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978sha256
- 252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816sha256
- 0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312sha256
- 6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9sha256
- 0x328a1fadff154290f0ce1389a4e633698cdfdaa7eth
- https://ipv4.ipleak.net/json/url
- https://get.geojs.io/v1/ip/geo.jsonurl
- https://ipapi.co/json/url
- https://api.ipapi.is/url
- https://ipinfo.io/jsonurl
- https://www.derp.ca/research/hellsuchecker-clickfix-etherhiding/#26-anti-sandbox-checks-and-a-nintendo-bypassurl
- https://cyberowi.pl/lumma-stealer-renpy-fitgirl-osmiowarstwowy-loader/url
- https://forums.malwarebytes.com/topic/338102-solution-of-gollopdevestdll-renpy-loader-malware-from-malwarebytes-blog/url
- 93.152.224.75ipv4
- 65.21.80.170ipv4
- 195.63.142.49ipv4
- bsc-dataseed.binance.orgdomain
- perfectverified.comdomain