ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://nelark.icu/xftaswx/res/post_proc.php?fpath=a.ps1.

Database Entry


IOC ID:1768929
IOC: https://nelark.icu/xftaswx/res/post_proc.php?fpath=a.ps1
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown RAT
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS40021 CONTABO-40021
Country:- DE
First seen:2026-03-17 07:02:20 UTC
Last seen:never
UUID:43e8e3b4-2194-11f1-9af6-42010aa4000a
Reporter kirkderp
Reward 5 credits from ThreatFox
Tags:lnk-dropper powershell uac-bypass

Avatar
kirkderp
LNK dropper chain: 1.pdf.lnk -> PS1 beacon -> fodhelper UAC bypass -> schtask persistence as SYSTEM -> C2 polling loop. nelark.icu on Contabo 195.26.242.135.