delphiaonline.top: a Windows malware download site with PowerShell and JavaScript stubs, and what to do if one ran

delphiaonline.top is a website that URLhaus lists for malware downloads: a JavaScript file and two PowerShell scripts both named secured_stub.ps1, all kept in open folders on the server. The site no longer answers when we look it up. If you ran a script or a pasted command from it on Windows, treat the PC as compromised: change your passwords from another device, then scan it offline.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with a script or file from delphiaonline.top, or a command that fetched a script from it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove delphiaonline.top (PowerShell and JavaScript stubs) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of three URLhaus entries for delphiaonline.top: two PowerShell files named secured_stub.ps1 and one JavaScript file, all offline on 29 September 2026
The three URLhaus entries for delphiaonline.top that we read on 10 October 2026, with the addresses defanged. Our own browser test could not find the site, so this table of reports is the main evidence.

Delphiaonline.top (PowerShell and JavaScript stubs): summary

TypeA malware download address for Windows: URLhaus lists two PowerShell stubs and one JavaScript file
RiskHigh if a script from it ran: passwords, sessions, crypto and a second hidden program are possible
SymptomsOften none. A file named secured_stub.ps1, a scheduled task you did not make, unknown Windows Security exclusions or a script you ran are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, check exclusions, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt
Our check (10 October 2026)One lookup: the name did not resolve, no page. A quiet or dead site clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 28 September 2026; malware URLs reported 29 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows, by the ps1 tag; no source says other systems are affected
Detection namesNo Microsoft detection name is known for the files on this server, because we did not open them and found no Microsoft page that names this campaign. The URLhaus tags are ps1, powershell, js, ascii and opendir. Run a Microsoft Defender Offline scan and read the name in Protection history
NameDelphiaonline.top
Domain registered28 September 2026
Evidence3 write-ups by security sites; details still limited
First seen29 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for delphiaonline.top, RDAP, one browser test of our own, and Microsoft Learn pages on the offline scan, Defender exclusions and PowerShell execution policy. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What delphiaonline.top is, and what we know about it

delphiaonline.top is a web address, not a program on your PC. It is a domain that the abuse.ch project URLhaus lists as a place where malware was served. No public write-up of this domain exists that we could find, and no report names a malware family for it, so this page rests on what URLhaus shows, what we saw ourselves and what Microsoft documents about the tools involved.

  1. 1

    What URLhaus lists

    Three file addresses on delphiaonline.top, all added on 29 September 2026 by the abuse.ch reporter account. At 07:09 UTC came https://delphiaonline[.]top/defounder/secured_stub.ps1. At 07:10 UTC came https://delphiaonline[.]top/mrdef/secured_stub.ps1 and https://delphiaonline[.]top/def/73yTfqg3w2y6fw4jE4h5dW.js. All three carry the threat type malware_download and were offline when we read them.

  2. 2

    What the tags mean

    ps1 and powershell say that two files are PowerShell scripts. js says that the third is a JavaScript file. ascii says all three are plain text, not compiled programs. opendir says the files sat in a server folder that anyone could list. No tag names a malware family, which is why this page does not claim one.

  3. 3

    What we could not confirm

    We did not download any of the files and we never saw a page that tells visitors what to do. So we do not know how a victim reached a script, what the stubs load, or whether the JavaScript file starts them. The tags are the reporter's labels, not our finding.

  4. 4

    What this means for you

    If you only saw the name in a log, a link or a warning, you are not infected by that alone. The risk is for people who opened a script file that reached out to this address, pasted a command that did, or ran a file that came from it.

Kind of threat
A malware download address: two PowerShell scripts and one JavaScript file, all plain text
Malware family
Not named by any source we found. The tags do not give one
Domain registered
28 September 2026, expires 28 September 2027, registrar Spaceship, Inc.; record last changed 28 September 2026 (RDAP, read 10 October 2026)
URLhaus entries
3 file addresses, all added on 29 September 2026; all 3 offline when we read them
Platform
Windows, by the ps1 tag. No source says which other systems are hit

What delphiaonline.top (PowerShell and JavaScript stubs) does on an infected PC

What we checked on 10 October 2026, and what we could not

We tried to open https://delphiaonline.top/ once, from Lithuania, in an automated Chromium browser set to English. The browser reported that the name could not be found, so no page loaded. That tells you nothing good about the site and it clears nothing.

Our site test, 10 October 2026

  • The name did not resolveOur browser reported ERR_NAME_NOT_RESOLVED. That means the domain name gave no address to connect to. URLhaus also lists all three files as offline, which fits a server that has been taken down or switched off.
  • Why that is not a clean resultA name that does not resolve can mean the operators removed the records, the hosting provider or registrar acted, or the attackers moved to another domain. It does not mean the files you may already have run are gone. Operators of this kind of site often rotate domains, so the same script may now point somewhere else.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
  • URLhaus listingThree malware addresses on this domain, two PowerShell scripts and one JavaScript file. All three were offline when we read the database.
  • Downloads and the page itselfWe did not download the files and we did not reach any page. We cannot tell you what the scripts contain.

Dangerous: treat it as a malware site The site test was one lookup that failed, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. A dead address does not heal a PC that already ran what it served.

What happened to delphiaonline.top, from registration to our test

The history is very short. The domain was registered on 28 September 2026 and the three malware addresses were reported the next morning, so the name looks bought for this purpose. The dates come from RDAP and from the URLhaus database.

  1. 28 September 2026

    The domain is registered

    RDAP shows delphiaonline.top registered on 28 September 2026 through the registrar Spaceship, Inc., valid until 28 September 2027. The name sounds like an online service; nothing we found shows a real business behind it.

  2. 29 September 2026

    Two PowerShell stubs and a JavaScript file are reported

    At 07:09 UTC URLhaus receives secured_stub.ps1 from the folder /defounder/. One minute later it receives secured_stub.ps1 from /mrdef/ and a JavaScript file with a random 22 character name from /def/. All three carry the tag opendir. This is the first and only time URLhaus sees the host.

    Table of the three URLhaus entries for delphiaonline.top with dates, status and tags
    The three URLhaus entries for delphiaonline.top as we read them on 10 October 2026. Addresses are defanged.
  3. 10 October 2026

    Our test finds no address

    Our browser visit to https://delphiaonline.top/ ends in ERR_NAME_NOT_RESOLVED, and URLhaus shows all three files offline. Eleven days after the reports, nothing answers.

We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.

The three files: what each name suggests, and what we do not know

File names are weak evidence. We list what each one could be and mark which statements are only a reading of the name and tags.

Four steps of a script stub chain: a JavaScript file runs, PowerShell fetches a stub, the stub does its work, and the PC should be treated as exposed
Our reading of the three files in four steps. We did not download them, so this is a guess from names and tags, not a description of their code.
Source: the URLhaus database, read 10 October 2026. The third column is our interpretation of the names and tags, not a finding.
File on delphiaonline.topWhat URLhaus saysWhat it may be (our reading)
/defounder/secured_stub.ps1Offline, tagged ascii, opendir, powershell and ps1, added 29 September 2026 at 07:09 UTCA plain text PowerShell script. The word stub usually means a small first part that fetches or starts something larger. Not confirmed
/mrdef/secured_stub.ps1Offline, same tags, added 29 September 2026 at 07:10 UTCA second script with the same file name in another folder. It may be a variant for a different target or a different build. Not confirmed
/def/73yTfqg3w2y6fw4jE4h5dW.jsOffline, tagged ascii, js and opendir, added 29 September 2026 at 07:10 UTCA JavaScript file with a random name. On Windows a .js file opens with Windows Script Host when you double click it, so it could be the part that starts a stub. Not confirmed

The folder names def, mrdef and defounder look like labels the operator chose for different batches. They might be short for defender, but we found no source that says so, and we do not claim the scripts touch Microsoft Defender. Treat the names as a reason to check your Defender settings, which the plan below does, and nothing more.

What the opendir tag tells you about the server

opendir means the folder listing of the server was open, so a researcher or any visitor could see the file names. It is a sign of a quickly set up server, and it is how the reporter found three files in three folders.

Our reading of the opendir tag and the registration date. No source we found describes this particular server.
What an open folder showsWhat it suggestsWhat it does not prove
Several files in one placeThe operator uploaded files by hand or with a simple tool and did not turn the listing offThat the same files were served to every visitor. Some servers send a different file by country or device
Folders with batch-like namesThe operator may keep separate copies for separate runs, mailings or targetsWhich batch reached which victim, or how many victims there were
A very new domainThe name was bought shortly before use. The registration here is one day older than the first reportWho bought it. RDAP in this case shows a registrar, not a person we could name

Because the folder was open when the reporter looked, the files were probably found by browsing the server, not by clicking a link in a message. That does not tell us how real victims were sent there, which stays unknown.

What delphiaonline.top (PowerShell and JavaScript stubs) can steal or download

Why a PowerShell stub can run even with Windows protections on

Many people believe that Windows will refuse to run a downloaded script. Microsoft's own documentation says the PowerShell execution policy is a safety feature, not a security boundary, and gives the reason.

  1. 1

    What the execution policy is

    Microsoft says the execution policy controls the conditions under which PowerShell loads configuration files and runs scripts. On Windows clients with no policy set, the effective policy is Restricted, which blocks script files but allows single commands.

  2. 2

    Why it does not stop a pasted command

    Microsoft's page states that the execution policy is not a security boundary: users can easily bypass it by typing the script contents at the command line. A command you paste into PowerShell is therefore not blocked by it.

  3. 3

    Why downloads by command are different

    Browsers mark downloaded files as coming from the internet, and the RemoteSigned policy then refuses unsigned ones. Microsoft notes that other download methods such as curl.exe, Invoke-RestMethod and Invoke-WebRequest may not add that mark. A script fetched by a command can lack the mark.

  4. 4

    What this means here

    A short command that downloads secured_stub.ps1 and runs it, or a JavaScript file that starts PowerShell, does not need you to change any setting. We do not know which route victims met, but the point is that the built-in rule is not the thing that protects you.

What a script stub could mean for you

We did not open the files and found no analysis of them, so we cannot list what this copy does. The table below is the general meaning of each kind of part, not a claim about this site's files.

Names and tags from the reports

  • ps1 and powershell (URLhaus tags on two files)
  • js (URLhaus tag on one file)
  • ascii (plain text files)
  • opendir (open folder listing)
  • secured_stub.ps1 (file name, two folders)
  • def, mrdef, defounder (folder names)
Sources: our reading of the URLhaus tags and Microsoft Learn, read 10 October 2026. None of these sources covers delphiaonline.top itself.
Kind of partWhat it can do to youSource
Stub or downloaderFetches and starts a larger program, so the first script may not be the last thing on the PCOur reading of the file name; not confirmed for this site
Script that changes security settingsSome scripts add exclusions or switch off protection before the real payload runs. We do not know if these do. Microsoft documents how exclusions work and how to list themMicrosoft Learn on Defender exclusions
Information stealer or remote toolCopies saved passwords, cookies and wallet files, or lets another person use the PC. Not named by any source for this domainGeneral risk of a malware download; not confirmed
PersistenceA scheduled task, Startup entry or Run key that starts the script again after a restartGeneral practice; not seen by us on this site

What this can cost you

Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where a script from the site ran or a file from it was opened.

  • High

    Logins your browser remembers

    A script that runs under your Windows account can reach whatever your browser stores. Reset passwords on another device and end all sessions, since the old session may outlive the old password.

  • High

    Lost cryptocurrency

    Treat wallet files and recovery phrases on the PC as seen by someone else. A transfer cannot be undone, so shift the balance to a fresh wallet created on a clean device first.

  • High

    A second program you cannot see

    A stub is made to bring something else. Until you have scanned from outside Windows, assume the PC may be running a program that the first script installed.

  • Medium

    Weakened protection

    If a script added exclusions to Windows Security, a later file in those folders would not be scanned. Check the exclusions list in the plan below.

  • Medium

    Work accounts and company data

    On a work PC the saved logins reach company systems. Tell your IT or security team at once; they can block the accounts.

  • Low

    Nothing, if you only saw the name

    A name in a warning, a firewall log or a blocked link is not an infection.

What you may notice, and what you may not

Many victims notice nothing. The signs below follow from how script chains are built; the first one is the best evidence you have.

Sources: URLhaus tags and Microsoft Learn, read 10 October 2026.
SignWhat it means
A script file or a pasted command you ran that mentions delphiaonline.top, secured_stub or a .top addressThis is the start of the chain. Note the file name or the line before you do anything else
A file named secured_stub.ps1 or a .js file with a long random name in Downloads, Temp or PublicThese are the names URLhaus lists. A match is a strong reason to follow the plan. Do not run it again
A scheduled task or a Startup entry you did not makeA common way for a script to start again at each logon. Note the name before you change anything
Exclusions in Windows Security that you did not addWindows Security lists folders and files it skips. An entry you do not recognise is a warning sign
A window that flashed and closedA PowerShell or Command Prompt window that runs a one-line download and exits
Accounts you did not touchLogins from new places, password-reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote
Nothing at allStubs and the programs they bring are built to stay quiet

How to check the PC for delphiaonline.top (PowerShell and JavaScript stubs)

How people end up running a script like this

We do not know how visitors reached delphiaonline.top, and no source says. These are the usual ways a .js or .ps1 file ends up running, listed so you can ask yourself which one fits.

  1. 1

    A script attachment or archive

    An email or a message carries a .js file, or a zip with one inside, named like an order, an invoice or a document. On Windows, double clicking a .js file runs it with Windows Script Host; it is not shown as a document.

  2. 2

    A command you are told to paste

    Some pages ask you to copy a command into the Windows Run box or PowerShell to pass a check or fix an error. The ps1 tag fits that way of starting a script, but no source tells us this site did so. We did not see its page.

  3. 3

    A file that claims to be an update or a free program

    Cracked software and fake updates are common carriers for downloader scripts. This is general knowledge, not something we saw on this domain.

  4. 4

    A link from a search result or an advert

    A new domain bought a day before use may be promoted by advertising or by links in messages. We have no evidence of which was used here.

Check your Windows PC before you delete anything

Start with the question that matters: did you open a script file or paste a command that fetched something from delphiaonline.top, or run a file that came from it? If yes, follow the numbered plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and network cables if you can.

Order of actions after a malicious script ran: disconnect, change passwords from another device, sign out and move crypto, check exclusions and run an offline scan, then reinstall Windows if in doubt
The order of actions after a script ran: accounts and crypto first, from another device; the PC last.
  1. 1

    Search for the file names

    Open File Explorer, click the search box and type secured_stub. Look in Downloads, C:\Users\Public and the Temp folder (type %TEMP% in the address bar). Do not double click anything you find. Note the folder and date.

  2. 2

    Open Task Scheduler

    Type Task Scheduler in the Start menu and open it. Click Task Scheduler Library and go through the list. For a task with a random or odd name, open its Actions tab and read the command. Leave it in place for now and write the name down.

  3. 3

    Open the Startup folder

    Hit Windows key + R, enter shell:startup and confirm. Anything in there that you did not put in yourself deserves a note.

  4. 4

    Read the Run history after a pasted command

    Start Registry Editor with regedit and browse to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Each value is something typed into the Run box. Only read them. Mark any that mention powershell, a web address or delphiaonline.

  5. 5

    Check the Windows Security exclusions

    Open Windows Security > Virus & threat protection > Manage settings > Add or remove exclusions. Every entry is a place that Windows Security does not scan. Any folder you did not add yourself is a warning sign. Microsoft's page says you usually do not need exclusions at all. An administrator can list them in PowerShell, as Microsoft documents, with Get-MpPreference and its ExclusionPath value. Note anything unknown and do not remove it until after the offline scan.

  6. 6

    Check Windows Security detections

    Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for detections dated around the time the script ran.

  7. 7

    Remember what a clean check means

    A downloader script may leave little on the disk once it has done its work. A clean check lowers the doubt; it does not remove it.

How to remove delphiaonline.top (PowerShell and JavaScript stubs)

How to remove delphiaonline.top

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to delphiaonline.top or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever delphiaonline.top installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows: Microsoft Defender Offline

An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.

  1. 1

    Get the PC ready

    Save open files and quit your programs, because the PC will restart by itself. The offline scan needs an administrator account and a working Windows Recovery Environment. Open Command Prompt with Run as administrator and type reagentc /info. If the status reads Disabled, type reagentc /enable. Microsoft warns that with recovery switched off the scan never starts and no error appears.

  2. 2

    Pause BitLocker first

    A PC with BitLocker on the system drive may demand the recovery key at the restart. Suspend BitLocker before you begin, using Microsoft's linked instructions, so the scan can start without a prompt.

  3. 3

    Launch it from Windows Security

    Go to Windows Security > Virus & threat protection > Scan options, tick Microsoft Defender Offline scan and press Scan now. Accept the two prompts. Windows signs you out and boots into a blue scanning screen. Microsoft says it takes about 15 minutes. As an administrator you can also type Start-MpWDOScan in PowerShell.

  4. 4

    Find what it caught

    When Windows returns, open Windows Security > Virus & threat protection > Protection history. Windows 10 reaches the same screen through Settings > Update & Security > Windows Security. Microsoft lists Windows on ARM as unsupported, and says Defender Antivirus must be your main antivirus.

  5. 5

    Tidy the exclusions

    Return to Add or remove exclusions and delete every entry you did not create. If you removed one, run the offline scan a second time, since the files in that folder were skipped on the first pass.

  6. 6

    Treat a clean report with care

    No detection is not proof of a clean PC when a script may have brought a second program. If one of these scripts really ran on your machine, copy your documents off and reinstall Windows.

If you use a Mac, an iPhone or an Android phone

The ps1 tag points at Windows. We found nothing that says the three files run on anything else.

Your deviceWhat we knowWhat to do
MacPowerShell exists for macOS, yet these files are tagged and named for Windows. What a Mac visitor would have seen is unknownHandle a Mac that ran something from this site as its own case, using our Mac guides. The Windows steps on this page do not apply
iPhone or iPadiOS does not run Windows scriptsNothing to delete. Change any password you typed into a page from this site
AndroidNo source we read mentions itNothing to delete for these files. Change any password you entered

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.

  1. 1

    New passwords, from a different device

    Pick up your phone or a family member's laptop. Begin with the email account, since it resets everything else, then bank, work and social logins. Anything typed on the affected PC should be assumed seen. Your Microsoft account has its own page at account.microsoft.com.

  2. 2

    End every open session

    Stolen browser cookies can keep a thief signed in after a password change. Use the sign out everywhere option in each account that matters, and cancel any API tokens, SSH keys or cloud keys that lived on the PC.

  3. 3

    Crypto before anything else

    If a wallet or its recovery phrase sat on the PC, create a new wallet on a clean device and send the funds there at once. A moved balance cannot be taken back, and neither can a stolen one.

  4. 4

    Add a second sign-in step

    Prefer an authenticator app or a hardware key over text messages. Then a stolen password alone, or one stolen session, does not let someone in at a fresh login.

  5. 5

    Save documents, then reset Windows

    Copy documents and photos only, never programs or scripts, to an external drive. On Windows 11 open Settings > System > Recovery; on Windows 10 open Settings > Update & Security > Recovery. Choose to reset the PC and remove everything.

  6. 6

    Keep an eye on the money

    For the next few weeks read your bank, email and crypto history for anything you did not do, and call your bank the same day if you find it.

Keep a Windows PC out of this kind of trap

The rule that stops this chain is short: a script file from an email or a web page is not a document, and a command from a web page is not a fix.

Do

  • Delete any .js, .vbs, .ps1 or .cmd file that reaches you by mail or download. It is a program, not a paper.
  • Close the tab when a page tells you to paste a command into Run or PowerShell.
  • Install Windows and browser updates, and leave Windows Security switched on.
  • Open the exclusions list in Windows Security once in a while and remove entries you never added.
  • Keep one backup on a drive that stays unplugged, and protect key accounts with an authenticator app.

Don't

  • Never open a purchase order or receipt that turns out to be a script, whatever it is called.
  • Never count on the PowerShell execution policy alone: Microsoft says it is not a security boundary.
  • Never run downloads from sites that offer paid software for free.
  • Never start a file that came by link or message and calls itself an update.
  • Never read a quiet scan as proof that you are safe.

Questions about delphiaonline.top (PowerShell and JavaScript stubs)

What is delphiaonline.top?

delphiaonline.top is a web address that URLhaus, the malware database run by abuse.ch, lists for malware downloads. Three file addresses were added on 29 September 2026: two PowerShell scripts named secured_stub.ps1 in different folders and one JavaScript file.

The domain was registered on 28 September 2026, one day earlier. When we looked it up on 10 October 2026 the name did not resolve, and URLhaus showed all three files offline. We found no public write-up of this domain and no malware family name for it.

Is delphiaonline.top a virus?

A website is not a virus, but this one is listed as a source of malware. URLhaus gives all three of its file addresses the threat type malware_download. We did not download the files, so we cannot say exactly what they do.

Treat the domain as dangerous, do not open it, and do not run anything it offers. Reading about it on this page cannot infect you. The danger is a script that you ran or a command that you pasted.

What is secured_stub.ps1?

secured_stub.ps1 is the file name of two PowerShell scripts that URLhaus lists on this domain, one in the folder defounder and one in mrdef. The ending .ps1 means a PowerShell script, and the tag ascii means it is plain text.

A stub usually means a small first part that fetches or starts something else. We did not open either file, so what they contain is not confirmed, and the name is only our clue.

I ran a script from delphiaonline.top. What do I do now?

Cut the PC off from the network by switching off Wi-Fi and pulling the cable. Next, working on a different device, reset your email, bank and work passwords, end your sessions and send any crypto to a new wallet.

Only then look at the exclusions list in Windows Security and start a Microsoft Defender Offline scan. When a script really ran, the surest finish is copying documents out and reinstalling Windows. On a work PC, call your IT team right away.

What if I only visited the site and ran nothing?

Probably nothing happened. Here the harm comes from running a script or file, not from loading a page. Leave anything it offered unopened, and delete a downloaded file you never ran.

If you typed a password into a page from this site, change it from a safe device. We never saw the page, so what it showed visitors is unknown, and today the site does not answer at all.

Why does the site not load any more?

Our browser got ERR_NAME_NOT_RESOLVED for delphiaonline.top on 10 October 2026, so the name pointed nowhere, and URLhaus marked every file offline. Possible reasons:

  • the operators deleted the records
  • the registrar or host stepped in
  • the campaign moved to a new domain

None of that repairs a PC that already ran a script from here, and a copy of the same script may call a different address today.

Does Windows block PowerShell scripts by default?

Only in part. On a Windows PC with no policy set, the effective PowerShell execution policy is Restricted, which blocks script files. But Microsoft's documentation says the execution policy is not a security boundary, because a user can type or paste the script contents at the command line instead.

Scripts fetched by curl.exe or Invoke-WebRequest may also lack the internet mark that some policies check. Do not count on it to protect you.

How do I check the Windows Security exclusions?

Open Windows Security, choose Virus and threat protection, then Manage settings, and scroll to Exclusions and select Add or remove exclusions. Each entry is a file, folder, type or process that Windows Security does not scan.

Microsoft says you usually do not need exclusions. Remove any entry you did not add yourself, after you have run the offline scan. An administrator can also list them in PowerShell with Get-MpPreference.

Will a scan with Windows Security remove it?

It may find parts of it, but a quiet scan does not prove the PC is clean. A downloader script may leave little on the disk after it has fetched its payload.

Run Microsoft Defender Offline from Windows Security under Virus and threat protection, Scan options, and read Protection history afterwards. If a script from this site ran, back up documents and reinstall Windows to be sure, and change your passwords from another device first.

Will Fortect remove delphiaonline.top?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For delphiaonline.top, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove uasputnik.com: a Windows ClickFix malware site serving .msi installers, and what to do if you ran one

uasputnik.com is a website that URLhaus lists for three Windows installer (.msi) malware downloads, two of them tagged ClickFix and one tagged Loader, and it refused our test connection. If you pasted a command from...TRHigh riskUgnius Kiguolis ·

Remove stanarcservice.com: a Windows ClickFix malware site (s.ps1) and what to do if you pasted its command

stanarcservice.com is a website that URLhaus lists for malware downloads, one of them a PowerShell script (s.ps1) tagged ClickFix, and it refused our test connection. If you pasted a command from it into the Windows...TRHigh riskUgnius Kiguolis ·

Remove reinigung-kosanke.de: a hacked WordPress site that served Formbook PowerShell scripts, and what to do

reinigung-kosanke.de is a German cleaning business website that URLhaus lists for four PowerShell (.ps1) malware downloads tagged Formbook, and it answered our test with a 503 error. If you ran a script from it,...TRHigh riskUgnius Kiguolis ·

Remove evacompltd.site: a Windows VIP Keylogger malware site (script files and PowerShell) and what to do if one ran

evacompltd.site is a website that URLhaus lists for malware downloads: The site no longer answers when we look it up. If you opened a script file that came from it on Windows, treat the PC as compromised: change your...TRHigh riskUgnius Kiguolis ·

Questions and experiences: delphiaonline.top (PowerShell and JavaScript stubs)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,444 members already hereReading, writing, commenting and voting. 0 verified · 169 joined this year