ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://v-k.com.ua/vcapcha.ps1.

Database Entry


IOC ID:1868124
IOC: https://v-k.com.ua/vcapcha.ps1
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS56851 VPS-UA-AS
Country:- UA
First seen:2026-08-04 06:59:42 UTC
Last seen:never
UUID:e4a82c19-8fce-11f1-8325-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:ClickFix Loader powershell

Avatar
Anonymous
ClickFix PowerShell stage-1 stager (sha256 cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0). Junk-code camouflaged; hides the PS window; POSTs a script_execution beacon to https://v-k.com.ua/reportv.php; downloads stage-2 https://v-k.com.ua/verifyc.ps1 to %TEMP%\verify_script.ps1, which pulls https://v-k.com.ua/notepad.b64 (base64-encoded PE final payload; family undetermined). Clipboard-delivered via compromised carrier guvenceliotoelektrik.com. Live HTTP 200 as of 2026-08-04.