The completed capture reached shellx.click. Captured artifacts contain suspicious evidence, but they do not establish an actionable abuse case.
The scanner reached the target and captured every planned artifact.
Each finding below is derived from a captured artifact. Expand one to see exactly what it was drawn from.
Captured page serves a PowerShell script that downloads 1.zip and 7za.exe from shellx.click, extracts with password '2', and executes Helper.exe.
Script sends PC name and country to conn.php and uploads base64 screenshots to cap.php on the same host after disabling Defender exclusions.
1 domains
No known kit signatures matched this capture.