ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://nelark.icu/xftaswx/res/post_proc.php?fpath=scheduler-once.

Database Entry


IOC ID:1768927
IOC: https://nelark.icu/xftaswx/res/post_proc.php?fpath=scheduler-once
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown RAT
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS40021 CONTABO-40021
Country:- DE
First seen:2026-03-17 07:02:17 UTC
Last seen:never
UUID:43412cbd-2194-11f1-9af6-42010aa4000a
Reporter kirkderp
Reward 5 credits from ThreatFox
Tags:lnk-dropper powershell uac-bypass

Avatar
kirkderp
LNK dropper chain: 1.pdf.lnk -> PS1 beacon -> fodhelper UAC bypass -> schtask persistence as SYSTEM -> C2 polling loop. nelark.icu on Contabo 195.26.242.135.