Threat Feed
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SSvyvfrfrB7D0fwTBPujyi6gUK8wJOnk9IuQ4v9ZC7LWp_qDggYl2dBBM4KhgCXIvNNNr1GHA&dsh=S369547207%3A1791678878596830
2026-10-11T01:37:36.010
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SSvyvfrfrB7D0fwTBPujyi6gUK8wJOnk9IuQ4v9ZC7LWp_qDggYl2dBBM4KhgCXIvNNNr1GHA&dsh=S369547207%3A1791678878596830
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Page uses exact same title as that of a popular online service
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
1/5
HTTPS page insecurely loads resources via HTTP
Phishing
macho_e2605e9e08fa
2026-10-11T01:00:11.813
malicious
macOS Executable
Close
macho_e2605e9e08fa
malicious
SHA256:
e2605e9e08fa9f7b1cc23497fec745f290a97a212cc7056c87459544325ac048
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads ssh keys
5/5
Malicious content matched by YARA rules
3/5
Reads credential files of the keychain
3/5
Query SIP status
2/5
Searches for sensitive application data
2/5
Searches for sensitive browser data
2/5
Creates an unusually large number of processes
2/5
Searches for sensitive mail data
2/5
Reads sensitive browser data
2/5
Reads sensitive mail data
2/5
Checks for existence of ssh keys
2/5
Suspicious content matched by YARA rules
1/5
Creates hidden file or folder
1/5
Connects to remote host
1/5
Tries to detect virtual machine
1/5
Content matched by YARA rules
Spyware
dissx86
2026-10-11T00:54:08.268
malicious
Linux ELF Executable (x86-64)
Close
dissx86
malicious
SHA256:
a14b14a477fc8f329f659e0bfa92c5888b478f4f5b35f71480c21ec7439728bc
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
2/5
Creates an unusually large number of processes
2/5
Deletes file after execution
2/5
Tries to execute downloaded binary of different architecture than the host
1/5
Clones process
1/5
Queries system time
1/5
Connects to remote host
1/5
Creates hidden file or folder
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Masquerades file extension
1/5
Downloads script
Downloader
BggFAePJuSCBmqoW
2026-10-11T00:53:32.368
malicious
macOS Executable
Close
BggFAePJuSCBmqoW
malicious
SHA256:
0a4578d60bd782b4e589dd85eb08ba64f4b4a24d167ef7d968eaed4411956aeb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads ssh keys
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Query SIP status
3/5
Reads credential files of the keychain
2/5
Searches for sensitive browser data
2/5
Creates an unusually large number of processes
2/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive mail data
2/5
Reads sensitive browser data
2/5
Reads sensitive mail data
2/5
Checks for existence of ssh keys
2/5
Searches for sensitive application data
1/5
Content matched by YARA rules
1/5
Connects to remote host
1/5
Tries to detect virtual machine
1/5
Creates hidden file or folder
Spyware
DIQXBQQ3VAVYuhuC.exe
2026-10-11T00:47:51.079
malicious
Windows Exe (x86-32)
Close
DIQXBQQ3VAVYuhuC.exe
malicious
SHA256:
929ef54d28d3d3275e3e8a4d0886f28dad12d1c04a8bd8b96920acb3b0183674
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Executes encoded PowerShell command
3/5
Modifies native system functions
3/5
Monitors keyboard input
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
2/5
Reads installed applications
2/5
Schedules task
2/5
Collects hardware properties
2/5
Queries OS info via WMI
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
CMD started with ambiguous arguments
1/5
Enables process privileges
1/5
Queries system time
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Reads system data
1/5
Creates mutex
1/5
Peripheral Device Discovery
1/5
Writes an unusually large amount of data to the registry
1/5
Possibly does reconnaissance
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
Spyware