Tracking PavinLoader across ClickFix and fake download campaigns
A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.
Indicators of Compromise
- domain: more-arpc.icu
- domain: rpcsecnoweb.pro
- domain: kelemet.shop
- domain: nexahub.lat
- domain: stellar-minds.cfd
- ip: 93.152.224.75
- domain: perfectverified.com
- domain: catalyst-pro.lat
- domain: twigoamwu.cfd
- domain: pinnacle-labs.lat
- domain: fimwoglea.shop
- domain: velodium.lat
- domain: echo-systems.cfd
- hash: bdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c
- hash: e3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9
- hash: a4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b
- hash: bf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e
- hash: 54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91
- hash: c1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb
- hash: 001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09
- hash: 2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978
- hash: 252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816
- hash: 0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312
- hash: 6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9
- hash: 0c7311a8b1e93a551f8c91f5d3a173d7
- hash: 2b224ccf0bbfc74d82202517c0e8c61a
- hash: 323cf31ab7b4cb38da910d7df2a89b17
- hash: 4397133d1c4b4f8dce5dc87bbe112073
- hash: 52a9c1f6d03a656cac5872daf45f2a5a
- hash: 98044793c18598442a796d77da57bc20
- hash: adbc54fdfc0f623130c62f3e9699089b
- hash: b2fe819dbb5a0e02d50973cc055373b8
- hash: c40224524a925451dadcad4452f8d4e8
- hash: 06cae19840cb14f053f0cbbec7329942f81167bf
- hash: 2f0b481d8f4075cf9b57e91777c0fd7b2e29975d
- hash: 3d71ec0a4f419ad1e347617de8b7d7a7589e43f1
- hash: 8c20118ae06e279c58ff0bb4e9b15f45b9868b65
- hash: 98a4ddec118de21e573709787b5e6cda66d6f8f5
- hash: 9e064619a2e36b2c3cdd5c38ad2f919165859604
- hash: ba1cf6e507981d355cdb395547259fde25590b81
- hash: cfd1eeaaa81c4133378190cc1d34379bd7f8afa9
- hash: e25982db20dc1272ea5a1d41c8c86c734c2e15df
- domain: cyberowi.pl
Tracking PavinLoader across ClickFix and fake download campaigns
Description
A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns"]
- Adversary
- null
- Pulse Id
- 6a8d406a23f75e32b69c2029
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmore-arpc.icu | — | |
domainrpcsecnoweb.pro | — | |
domainkelemet.shop | — | |
domainnexahub.lat | — | |
domainstellar-minds.cfd | — | |
domainperfectverified.com | — | |
domaincatalyst-pro.lat | — | |
domaintwigoamwu.cfd | — | |
domainpinnacle-labs.lat | — | |
domainfimwoglea.shop | — | |
domainvelodium.lat | — | |
domainecho-systems.cfd | — | |
domaincyberowi.pl | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip93.152.224.75 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashbdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c | — | |
hashe3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9 | — | |
hasha4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b | — | |
hashbf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e | — | |
hash54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91 | — | |
hashc1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb | — | |
hash001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09 | — | |
hash2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978 | — | |
hash252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816 | — | |
hash0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312 | — | |
hash6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9 | — | |
hash0c7311a8b1e93a551f8c91f5d3a173d7 | — | |
hash2b224ccf0bbfc74d82202517c0e8c61a | — | |
hash323cf31ab7b4cb38da910d7df2a89b17 | — | |
hash4397133d1c4b4f8dce5dc87bbe112073 | — | |
hash52a9c1f6d03a656cac5872daf45f2a5a | — | |
hash98044793c18598442a796d77da57bc20 | — | |
hashadbc54fdfc0f623130c62f3e9699089b | — | |
hashb2fe819dbb5a0e02d50973cc055373b8 | — | |
hashc40224524a925451dadcad4452f8d4e8 | — | |
hash06cae19840cb14f053f0cbbec7329942f81167bf | — | |
hash2f0b481d8f4075cf9b57e91777c0fd7b2e29975d | — | |
hash3d71ec0a4f419ad1e347617de8b7d7a7589e43f1 | — | |
hash8c20118ae06e279c58ff0bb4e9b15f45b9868b65 | — | |
hash98a4ddec118de21e573709787b5e6cda66d6f8f5 | — | |
hash9e064619a2e36b2c3cdd5c38ad2f919165859604 | — | |
hashba1cf6e507981d355cdb395547259fde25590b81 | — | |
hashcfd1eeaaa81c4133378190cc1d34379bd7f8afa9 | — | |
hashe25982db20dc1272ea5a1d41c8c86c734c2e15df | — |
Threat ID: 6a8d73d1acd9273b490ff983
Added to database: 08/25/2026, 10:52:01 UTC
Last updated: 08/25/2026, 16:29:26 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.