Threat Feed
file.exe
2026-09-30T21:20:28.632
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
b3cff9bf1f9e94845188e2d6e8094d02f16686fbd0cf0c1866d9cb1f8cc4cb9c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
5/5
Stealcv2 configuration was extracted
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
4/5
APC Injection
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
3/5
Modifies system configuration
3/5
Takes screenshot
3/5
Uses HTTP to upload a large amount of data
3/5
Suspicious content matched by YARA rules
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
3/5
Bypasses browser App-Bound Encryption
3/5
Tries to detect the presence of antivirus software
3/5
Disables a crucial system service
3/5
Modifies Windows Defender configuration
2/5
Tries to detect a forensic tool
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Searches for sensitive browser data
2/5
Schedules task
2/5
Tries to detect application sandbox
2/5
Allows invalid SSL certificates
2/5
Disables a system tool
2/5
Reads installed applications
2/5
Reads sensitive browser data
2/5
Searches for sensitive VPN configuration data
2/5
Searches for sensitive FTP data
2/5
Tries to detect analyzer sandbox
2/5
Creates an unusually large number of processes
2/5
Suspicious content matched by YARA rules
1/5
Executes dropped PE file
1/5
Content matched by YARA rules
1/5
Installs system service
1/5
Creates process with hidden window
1/5
Possibly does reconnaissance
1/5
Modifies operating system directory
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Installs system startup script or application
1/5
Query OS Information
1/5
A monitored process crashed
1/5
Enumerates running processes
1/5
Query CPU Properties
1/5
Queries system time
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Installs kernel driver
1/5
URL contains a TLD highly associated with phishing
Spyware
Injector
file.exe
2026-09-30T21:20:19.101
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
2a3c7c18b53e6ffa5d5787a979fbdf3bfe3149421f3f87ba5a71ccfe7871ac47
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Peripheral Device Discovery
2/5
Reads installed applications
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates a page with write and execute permissions
1/5
Queries system time
Injector
https://account-verifica-page.vercel.app/privacy-centers.html
2026-09-30T21:08:37.488
malicious
URL
Close
https://account-verifica-page.vercel.app/privacy-centers.html
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious content matched by YARA rules
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
2/5
Page is served from a service commonly used for temporary hosting
1/5
Checks external IP address
1/5
Content matched by YARA rules
1/5
Resource is loaded from a service commonly used for temporary hosting
Phishing
https://mylewisph.com/xcvbn/pages/info.php
2026-09-30T20:35:41.355
malicious
URL
Close
https://mylewisph.com/xcvbn/pages/info.php
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
4/5
Page contains a branded form for credit card details
2/5
Page is hosted on a recently registered domain
2/5
Page uses exact same title as that of a popular online service
1/5
Logon form detected via Computer Vision
1/5
Page secured via a Domain Validated SSL certificate
1/5
Page uses exact favicon of a popular online service
Phishing
df7d1c55dee47ba59bab39550a68585d9416ad3f5b8e9a4542de77f71510e77b.html
2026-09-30T19:56:42.996
malicious
HTML Document
Close
df7d1c55dee47ba59bab39550a68585d9416ad3f5b8e9a4542de77f71510e77b.html
malicious
SHA256:
df7d1c55dee47ba59bab39550a68585d9416ad3f5b8e9a4542de77f71510e77b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
TelegramPhishkit configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Sends data via a Telegram bot
1/5
Checks external IP address
1/5
Loads resources from a public service
1/5
URL contains a TLD highly associated with phishing
1/5
Resource is loaded from a service commonly used for temporary hosting
1/5
Page contains clickables with luring keywords
Phishing