URLhaus Database

You are currently viewing the URLhaus database entry for http://79.124.59.142/index.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3806858
URL: http://79.124.59.142/index.ps1
URL Status:Offline
Host: 79.124.59.142
Date added:2026-03-28 07:03:17 UTC
Last online:2026-05-03 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-03-28 07:04:11 UTC to noc{at}4vendeta[dot]com)
Takedown time:1 month, 6 days, 16 hours, 22 minutes Bad (down since 2026-05-03 23:26:59 UTC)
Tags:ACRStealer ascii powershell ps1 ZigClipper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-30index.ps1ps1 6bef1b7ac491dddc98973b2d8f0fa44ddb6f4350ec522bb5ee516c5841ff7bd6n/a 
2026-04-28index.ps1ps1 ac277422596c22997b7d700de1087a298613faca5eca35116f610a87ae9d733cn/a 
2026-04-24index.ps1ps1 9fd5d37eea2a4365501465a2466c740ca2624e5ff56945f8ea0ecf1039ca825cn/a 
2026-04-08index.ps1ps1 0ab26337ef9b0f330001540e66c814a556b9434ccf1bea1f3dc7cd7f7158b2d6n/a
2026-03-30index.ps1ps1 12a718244ed2ee07d5bf020cde7afdb9e3b3bc2ad4a84c7c8021cbc4df5d9fa7n/a
2026-03-28index.ps1ps1 3fb70248e9db2bfd2d8d4ad60b752fc3fd9b442b58a30f8239da561e82a791f3n/aZigClipper