Sysraw Stealer

Aliases: Clipsa

Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 15:22:06

Context

Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe". PDB strings suggest the name "Clipsa" though. First stage connects to /WPCoreLog/, the second one to /WPSecurity/. Its behavior suggest that it is an info stealer. It creates a rather large amount of files in a subdirectory (e.g. data) named "1?[-+].dat" and POSTs them.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Sysraw Stealer (report)
  • decoded.avast.io — Clipsa Multipurpose Password Stealer (report)
  • zerophagemalware.com — Rig Ek Via Rulan Drops An Infostealer (report)

External references