Skip to content

Campaign record

ModeloRAT via a fake CrashFix popup

ModeloRAT delivered after a fake ad-blocker extension crashes the victim's browser

Status as last assessed
Active
First seen
Unrecorded
Last seen
Unrecorded
Indicators
20
Sources
1
Targets
Windows
  • Fake error dialog
  • ModeloRAT
  • Malicious browser extension
  • Malvertising

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Microsoft Defender Experts reported this activity on 5 February 2026, having first identified it the month before, and gave the variant the name CrashFix. The chain starts with an advertisement shown to people looking for an ad blocker; the ad leads to the official Chrome Web Store and an extension posing as uBlock Origin Lite. After a delay the extension traps the browser in a loop and shows a counterfeit repair warning, which tells the visitor to run a pasted command in the Windows dialog box. That command copies the built-in finger utility under another name to pull obfuscated PowerShell from an attacker address. On a domain-joined machine the script fetched a portable Python bundle and a Python remote access trojan Microsoft names ModeloRAT, which beacons over plain HTTP, persists through a Run key, and pulled a further payload from Dropbox.

Overlap with other campaigns

We compared the 20 indicators in this record — covering 2 distinct registrable domains — against the 43 other published campaigns in this corpus.

  • No indicator is shared, but the two records use the same registrable domains.

    Shared registrable domain (1)

    • domain, shown defanged for safety: dropbox dot com

A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
Clipboard injection15 of 4434%T1204.004
finger.exe payload retrieval1 of 442%

No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

20 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
url, shown defanged for safety: hxxps colon slash slash www dot dropbox dot com/scl/fi/znygol7goezlkhnwazci1/a1 dot zipurlDownload URLShared platformReport an error in url record 7fb6fd6c-18e2-4dcc-941e-75563d473d27
ip, shown defanged for safety: 144 dot 31 dot 221 dot 179ipPayload hostAttacker-controlledReport an error in ip record 4012cfc6-9ea7-43d5-ac90-e4d9036ddf8c
ip, shown defanged for safety: 144 dot 31 dot 221 dot 197ipPayload hostAttacker-controlledReport an error in ip record 76e3915a-3cff-453f-abc1-4b7c63bd3fbb
ip, shown defanged for safety: 199 dot 217 dot 98 dot 108ipPayload hostAttacker-controlledReport an error in ip record 91ee583b-d7a4-477e-9541-e25be9996c93
domain, shown defanged for safety: nexsnield dot comdomainCommand and controlAttacker-controlledReport an error in domain record 9d503931-857d-4b1b-9bc6-16b6c211b283
ip, shown defanged for safety: 158 dot 247 dot 252 dot 178ipCommand and controlAttacker-controlledReport an error in ip record 1ba116ed-4f4e-43c6-b8a2-8ef402213430
ip, shown defanged for safety: 170 dot 168 dot 103 dot 208ipCommand and controlAttacker-controlledReport an error in ip record 3acdc1e7-75fa-4c0e-8ff1-952532511239
ip, shown defanged for safety: 69 dot 67 dot 173 dot 30ipCommand and controlAttacker-controlledReport an error in ip record 3baaa116-e99b-48e5-9061-55b4e7c6eed7
filename, shown defanged for safety: cpcdkmjddocikjdkbbeiaafnpdbdafmi_42974 dot crxfilenameSampleNot yet assessedReport an error in filename record 8628a69a-c924-4a6e-84e0-a44c54078d9e
filename, shown defanged for safety: extentions dot pyfilenameSampleNot yet assessedReport an error in filename record f44daeb6-070b-45eb-ae30-3c7be12d37c7
filename, shown defanged for safety: modes dot pyfilenameSampleNot yet assessedReport an error in filename record 104c0971-165f-42c6-8f97-b1c89f9ae3ed
filename, shown defanged for safety: udp dot pywfilenameSampleNot yet assessedReport an error in filename record ca30fb07-9da4-47aa-abc1-b05b45bc7326
sha256, shown defanged for safety: 01eba1d7222c6d298d81c15df1e71a492b6a3992705883c527720e5b0bab701asha256SampleNot yet assessedReport an error in sha256 record ce954b8f-2d28-485d-b857-2892d418e6d0
sha256, shown defanged for safety: 37b547406735d94103906a7ade6e45a45b2f5755b9bff303ff29b9c2629aa3c5sha256SampleNot yet assessedReport an error in sha256 record 9f24b8cc-957e-4703-8eee-13b7cdeae909
sha256, shown defanged for safety: 3a5a31328d0729ea350e1eb5564ec9691492407f9213f00c1dd53062e1de3959sha256SampleNot yet assessedReport an error in sha256 record d5bf7943-4c8c-44a6-b30a-d98993aa5b90
sha256, shown defanged for safety: 6461d8f680b84ff68634e993ed3c2c7f2c0cdc9cebb07ea8458c20462f8495aasha256SampleNot yet assessedReport an error in sha256 record 6c8d1091-0ccc-4ab6-83e3-0dd0bc4293b8
sha256, shown defanged for safety: 6f7c558ab1fad134cbc0508048305553a0da98a5f2f5ca2543bc3e958b79a6a3sha256SampleNot yet assessedReport an error in sha256 record f4ff0eb8-201e-439a-b020-e77689a9180c
sha256, shown defanged for safety: c46af9ae6ab0e7567573dbc950a8ffbe30ea848fac90cd15860045fe7640199csha256SampleNot yet assessedReport an error in sha256 record 2d0dd7ba-4a71-431d-8194-0751222d2375
sha256, shown defanged for safety: c76c0146407069fd4c271d6e1e03448c481f0970ddbe7042b31f552e37b55817sha256SampleNot yet assessedReport an error in sha256 record ddad6cd9-da9f-43a9-aa1a-3184a7cf17fe
filename, shown defanged for safety: ct dot exefilenameOtherNot yet assessedReport an error in filename record 6995c0c8-6b24-4928-8061-3fbbf95ee267

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “ModeloRAT via a fake CrashFix popup”, campaign ID 7d88b9bf, retrieved 2026-08-29, snapshot fb0eed7.

https://clickfixreport.com/campaigns/7d88b9bf/crashfix-python-rat-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.