Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Investigating a Multi-Stage PowerShell Loader

e04487377e4f976ac18e7c1c5b22bc85e03b4423e73fd490e9d1641758faac81

TLP:CLEAR
Active

SHA-256 Hash

Description

A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Analysis revealed heavily obfuscated PowerShell stages utilizing Base64 encoding, XOR-based obfuscation with the key 'Write', dynamically constructed IEX commands, and hidden PowerShell execution. A decoy 'Verification complete!' message disguised as Google.com was presented to victims during execution. Multiple Vercel instances hosted additional artifacts including loader scripts and executables. The initial infection vector remains unidentified, suggesting these PowerShell-hosting URLs represent second-stage delivery points in a multi-stage attack chain.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Investigating a Multi-Stage PowerShell Loader
Pattern Type
STIX
Confidence
75%
Valid From
Aug 10, 2026 18:01
Total Sightings
0
Added
Aug 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of e04487377e4f976ac18e7c1c5b22bc85e03b4423e73fd490e9d1641758faac81

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.