Skip to content

Infostealer

Sysraw Stealer

aka Clipsa

Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe".

Sysraw Stealer, also known as Clipsa, is a Windows infostealer.

Background

The Sysraw stealer takes its name from the fact that at one point it ran as "ZSysRaw\sysraw.exe", though PDB strings point to the name "Clipsa". Its first stage reaches out to /WPCoreLog/ and the second to /WPSecurity/. The malware behaves like an info stealer, generating a fairly large number of files named "1?[-+].dat" inside a subdirectory (for example, data) and then POSTing them.


Source: Malpedia (Fraunhofer FKIE).