ThreatFeed
Technology
VMRay DeepResponse
Resources
Try VMRay
Threat Feed
Filter by Classification
Adware
Backdoor
Banker
Banking Trojan
Bot
Crypter
Crypter
Dialer
Downloader
Dropper
Eicar
EICAR
Exploit
Hacktool
HackTool
Injector
Jigsaw
Keylogger
Miner
Phishing
POS
Pua
PUA
Ransomware
RAT
Remote Access Trojan
Rootkit
Skylock
Spyware
Stealer
Trojan
Virus
Wiper
Worm
Xorist
Filter by Sample Type
Apple Script
Excel Document
HTML Application
HTML Application (Shell Link)
HTML Document
Java Archive
Java Class
JScript
Linux ELF Executable (x86-64)
macOS App
macOS Executable
Microsoft Access Database
Microsoft Publisher Document
MSI Setup
PDF Document
Powerpoint Document
PowerShell Script
PowerShell Script (Shell Link)
Python Script
RTF Document
Shell Script
URL
VBScript
Windows ActiveX Control (x86-32)
Windows ActiveX Control (x86-64)
Windows Batch File
Windows Batch File (Shell Link)
Windows DLL (x86-32)
Windows DLL (x86-64)
Windows Driver (x86-32)
Windows Driver (x86-64)
Windows Exe (x86-32)
Windows Exe (x86-64)
Windows Help File
Windows Script File
Word Document
Search
1
2
522200
>
https://f005.backblazeb2.com/b2api/v1/b2_download_file_by_id?fileId=4_zcc7c1d666af4a950a60f051f_f104156febf7cf14c_d20260916_m073132_c005_v0501037_t0048_u01789543892927#a@b.com
2026-09-19T08:11:28.735
malicious
URL
Details
Close
https://f005.backblazeb2.com/b2api/v1/b2_download_file_by_id?fileId=4_zcc7c1d666af4a950a60f051f_f104156febf7cf14c_d20260916_m073132_c005_v0501037_t0048_u01789543892927#a@b.com
malicious
SHA256:
VMRay Threat Identifiers
Severity
Operation
5/5
TelegramPhishkit configuration was extracted
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Phishing page detected via Machine Learning
2/5
Page is served from a service commonly used for temporary hosting
1/5
Page secured via a Domain Validated SSL certificate
1/5
URL does not use standard port
1/5
Tries to connect using an uncommon port
1/5
Page presents itself as a logon page
1/5
URL contains email address
1/5
Logon form detected via Computer Vision
1/5
Page contains a form with unusual text spacing
Full Report
Close
Phishing
Full Report
https://wyseservices.in/sohn/a2/PseUK0R7WEnu1B9mHAebCHAkIKSlcDxzA4a80b4c580swZrxdDwx3w8bdWkUdx5AmXXDzuZe3HS9SRlvsbMo8khW3MckLAsezb0OMC8NVvSRz2CNor8LECrC30olav6MrB8uxR73B6hbv55zN7oOauuKOoDkIM6xxZK13z6XiuEW2VKmI8db9Bs.html?email=loris1@c875c1e41bc9d40050aca92d1daca9a2b30a.net
2026-09-19T08:10:59.909
malicious
URL
Details
Close
https://wyseservices.in/sohn/a2/PseUK0R7WEnu1B9mHAebCHAkIKSlcDxzA4a80b4c580swZrxdDwx3w8bdWkUdx5AmXXDzuZe3HS9SRlvsbMo8khW3MckLAsezb0OMC8NVvSRz2CNor8LECrC30olav6MrB8uxR73B6hbv55zN7oOauuKOoDkIM6xxZK13z6XiuEW2VKmI8db9Bs.html?email=loris1@c875c1e41bc9d40050aca92d1daca9a2b30a.net
malicious
SHA256:
VMRay Threat Identifiers
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
2/5
Branded Logon form detected via Computer Vision
1/5
Page secured via a Domain Validated SSL certificate
1/5
URL contains email address
1/5
Page contents are loaded dynamically
1/5
Page contains clickables with luring keywords
1/5
Checks external IP address
1/5
Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
URL contains a TLD highly associated with phishing
1/5
Resource is loaded from a service commonly used for temporary hosting
1/5
Page presents itself as a logon page
Full Report
Close
Phishing
Full Report
f5c02265641a8234ab89db934cb8379528dfb9e2c6ae17bfc49811421a383171.exe
2026-09-19T07:30:37.092
malicious
Windows Exe (x86-32)
Details
Close
f5c02265641a8234ab89db934cb8379528dfb9e2c6ae17bfc49811421a383171.exe
malicious
SHA256: f5c02265641a8234ab89db934cb8379528dfb9e2c6ae17bfc49811421a383171
VMRay Threat Identifiers
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Reads network adapter information
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
1/5
Enables process privileges
1/5
Connects to remote host
Full Report
Close
Backdoor
Full Report
8b4caad4c51a87f10977d3fecd40938d5201bb9d8762a9d728c3c0454ba5e414.exe
2026-09-19T07:27:05.372
malicious
Windows Exe (x86-64)
Details
Close
8b4caad4c51a87f10977d3fecd40938d5201bb9d8762a9d728c3c0454ba5e414.exe
malicious
SHA256: 8b4caad4c51a87f10977d3fecd40938d5201bb9d8762a9d728c3c0454ba5e414
VMRay Threat Identifiers
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
1/5
Tries to detect application sandbox
1/5
Connects to remote host
1/5
Unusual large memory allocation
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Enables process privileges
1/5
Resolves API functions dynamically
1/5
Queries system time
Full Report
Close
Backdoor
Full Report
8b60b132edfe051a17e79883e0da471f21c50804fbb7d1b2fdbc7ed5d606d9ed.exe
2026-09-19T07:26:16.268
malicious
Windows Exe (x86-32)
Details
Close
8b60b132edfe051a17e79883e0da471f21c50804fbb7d1b2fdbc7ed5d606d9ed.exe
malicious
SHA256: 8b60b132edfe051a17e79883e0da471f21c50804fbb7d1b2fdbc7ed5d606d9ed
VMRay Threat Identifiers
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Connects to remote host
Full Report
Close
Backdoor
Downloader
Full Report
1
2
522200
>