Threat Feed
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SRNOfGhNdEaL3CuHkNDx6URJdWwu7NdBR9LHg6oMNxEXFuoCHbXvSLGxV5N7VMSNMWWSrQyFg&dsh=S772269775%3A1790971354820402
2026-10-02T21:24:26.937
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SRNOfGhNdEaL3CuHkNDx6URJdWwu7NdBR9LHg6oMNxEXFuoCHbXvSLGxV5N7VMSNMWWSrQyFg&dsh=S772269775%3A1790971354820402
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Page uses exact same title as that of a popular online service
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
1/5
HTTPS page insecurely loads resources via HTTP
Phishing
123.exe
2026-10-02T20:55:53.383
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
eef3bc30d9787d1b3b7363f9453d82db9dd51950cc9fd32f385efa1aaaee1126
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious file detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Sets up server that accepts incoming connections
2/5
Reads network adapter information
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
1/5
Query OS Information
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Enables process privileges
1/5
Unusual large memory allocation
1/5
Queries system time
PUA
Miner
ok.exe
2026-10-02T20:55:33.713
malicious
Windows Exe (x86-64)
Close
ok.exe
malicious
SHA256:
05b1adb6b6f619a75035a5c27521374b47e60f8337cf52d7379b7ff3c64ee7fe
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
4/5
Creates elevated child process
3/5
Executes code with kernel privileges
3/5
Suspicious file detected via reputation
2/5
Creates a new process from a system binary
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
2/5
Reads network adapter information
2/5
Sends control codes to a driver
1/5
Query OS Information
1/5
Enables process privileges
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Unusual large memory allocation
1/5
Queries system time
PUA
Miner
123.exe
2026-10-02T20:55:25.336
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
7381ba6cf8911566478f150f5db4b2921e8db8dfa12babd1e19dd753bb0434b2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Reads network adapter information
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
1/5
Content matched by YARA rules
1/5
Connects to remote host
1/5
Performs DNS request
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner
123.exe
2026-10-02T20:54:52.489
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
8823abc60f6f320bd76220ebb51ce76c49e5e9339b3bfbf716122653fa3fe2b1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Reads network adapter information
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
1/5
Content matched by YARA rules
1/5
Connects to remote host
1/5
Performs DNS request
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner