Investigating a Multi-Stage PowerShell Loader

Reported 10 Aug 2026 by otx · Severity: medium

A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Gr