Researchers documented a multi-stage PowerShell malware delivery chain that served script content directly from 203[.]188[.]171[.]166 and dorenzaa[.]com, then pulled additional payloads from Vercel-hosted infrastructure. The observed chain downloaded archives and executables including Grape2.zip, UltraToolliteSetup.exe, and draw.zip, extracted them into user directories such as %LOCALAPPDATA%\jsDownload and %APPDATA%, and launched files including Grape.exe. Investigators said the infrastructure behaved like a staged loader rather than a normal website, with multiple remote components used to fetch and run follow-on payloads.
The PowerShell loaders used hidden execution, dynamically constructed IEX, Base64 decoding, and repeating-key XOR obfuscation with the key "write", while displaying a decoy prompt reading "Verification complete!" under the window title "Google.com". Analysts published indicators including the IP address, domain, file names, hashes, and execution paths, but said the initial infection vector and the ultimate functionality of several downloaded executables remained undetermined, and no threat actor attribution was made.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
A post on r/netsec referenced the analysis of the multi-stage PowerShell payload chain and shared initial indicators including 203[.]188[.]171[.]166 and dorenzaa[.]com. The post highlighted obfuscated loaders, hidden execution, Base64 and XOR decoding, and the decoy "Verification complete!" prompt.
The file 4_27_1.txt was identified as another heavily obfuscated PowerShell loader. After deobfuscation, it was shown to download draw.zip, save it as %APPDATA%\draw.zip, extract it into %APPDATA%\Default, and execute %APPDATA%\Default\draw.io.exe; the reported SHA-256 for draw.zip was a25bbc466416f65726c5e3f587f69515dd003f114c1eab29fdfca7b52fbd74b1.
Analysis of the heavily obfuscated loader1.txt showed it decoded embedded Base64 data and applied a repeating-key XOR using the key "write." The deobfuscated script downloaded UltraToolliteSetup.exe, saved it as %APPDATA%\UltraToolliteSetup.exe, and executed it; the reported SHA-256 was d8620f4df9e0159a8db675868b4ed9a205638c847439f52cf1c88541d0655a64.
The investigation found loader2.txt and loader22.txt contained the same PowerShell stager, with SHA-256 f139bd347cba0b197c97ca084c224d8c779bdb9116a5327e9cf30b0f72a59530. The stager launched hidden PowerShell, downloaded loader1.txt, dynamically constructed IEX, and displayed a decoy "Verification complete!" prompt titled "Google.com."
The analysis identified a second Vercel host, file-host-5kidy7ph1-nyererebill-sudos-projects[.]vercel[.]app, hosting files including UltraToolliteSetup.exe, mat.zip, draw.zip, loader1.txt, loader2.txt, loader22.txt, 1.txt, and 4_27_1.txt. The content notes that co-location on the same Vercel instance alone does not prove all files belong to one campaign.
PowerShell retrieved Grape2.zip from file-host-alpha[.]vercel[.]app, created %LOCALAPPDATA%\jsDownload, extracted the archive there, and executed %LOCALAPPDATA%\jsDownload\Grape.exe. The reported SHA-256 for Grape2.zip was 3eaf786bfb4ae5688b347511f98d74c948b7dc0749558acbdc6bbe33dcfa3a61.
The investigation identified 203[.]188[.]171[.]166 and dorenzaa[.]com as locations serving PowerShell code directly rather than normal web content, likely acting as second-stage delivery points. The initial infection vector was not identified.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcemalware.news
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.