{"id":"3f65f2e2a66c01de0b412b236f23ce81","title":"Crypto-Clipper — Crypto-Clipper · 加密货币剪贴板劫持器 · PE64","md5":"3f65f2e2a66c01de0b412b236f23ce81","sha256":"35affffe7d3ef594249fd4f657ff616180e864285d89f389c296e51465db514b","family":"Crypto-Clipper","apt":null,"verdict":null,"sample_type":"加密货币剪贴板劫持器","lang":"Rust","file_format":"PE64","compiler":"Rust","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为多层投递的加密货币剪贴板劫持器（Clipper）。Stage 0 为 Rust 引导 + PyInstaller 打包、PyArmor 保护的 Python installer.pyc；内嵌载荷统一使用 12 字节 XOR 密钥 8QwGZ19LN86w 加密。解密后得到：① uusd.exe（MinGW PE64，内嵌 Tor 客户端）用于匿名 C2；② 004_b.js / 004_n.js 高度混淆的剪贴板劫持脚本；③ 004.xml 为 Windows 任务计划 XML（wscript.exe 每 1 分钟执行 JS）；④ 004w.txt / 004a.txt 为字典词表。JS 核心逻辑：监控剪贴板，检测并窃取 BIP39 助记词（12 词）、私钥，并按格式替换 BTC（1xxx/3xxx/bc1q/bc1p）、TRON（T 开头）、Monero（4/8 开头 95 字符）地址为攻击者地址，随后截图并通过 Tor 洋葱地址（sqwzutzq7b3ad.onion 等）回传。","url":"https://zseceye.com/report/3f65f2e2a66c01de0b412b236f23ce81","json_url":"https://zseceye.com/report/3f65f2e2a66c01de0b412b236f23ce81.json","html_url":"https://zseceye.com/report/3f65f2e2a66c01de0b412b236f23ce81","hash_urls":{"md5":"https://zseceye.com/hash/3f65f2e2a66c01de0b412b236f23ce81","sha256":"https://zseceye.com/hash/35affffe7d3ef594249fd4f657ff616180e864285d89f389c296e51465db514b"},"search_urls":{"md5":"https://zseceye.com/?q=3f65f2e2a66c01de0b412b236f23ce81","sha256":"https://zseceye.com/?q=35affffe7d3ef594249fd4f657ff616180e864285d89f389c296e51465db514b"},"sample_download_url":"https://zseceye.com/report/3f65f2e2a66c01de0b412b236f23ce81/sample","sample_filename":"35affffe.zip","iocs":[],"ips":[]}