ThreatFeed
Technology
VMRay DeepResponse
Resources
Try VMRay
Threat Feed
Filter by Classification
Adware
Backdoor
Banker
Banking Trojan
Bot
Crypter
Crypter
Dialer
Downloader
Dropper
Eicar
EICAR
Exploit
Hacktool
HackTool
Injector
Jigsaw
Keylogger
Miner
Phishing
POS
Pua
PUA
Ransomware
RAT
Remote Access Trojan
Rootkit
Skylock
Spyware
Stealer
Trojan
Virus
Wiper
Worm
Xorist
Filter by Sample Type
Apple Script
Excel Document
HTML Application
HTML Application (Shell Link)
HTML Document
Java Archive
Java Class
JScript
Linux ELF Executable (x86-64)
macOS App
macOS Executable
Microsoft Access Database
Microsoft Publisher Document
MSI Setup
PDF Document
Powerpoint Document
PowerShell Script
PowerShell Script (Shell Link)
Python Script
RTF Document
Shell Script
URL
VBScript
Windows ActiveX Control (x86-32)
Windows ActiveX Control (x86-64)
Windows Batch File
Windows Batch File (Shell Link)
Windows DLL (x86-32)
Windows DLL (x86-64)
Windows Driver (x86-32)
Windows Driver (x86-64)
Windows Exe (x86-32)
Windows Exe (x86-64)
Windows Help File
Windows Script File
Word Document
Search
1
2
520601
>
https://site-3da5qr19c.godaddysites.com
2026-08-23T20:16:15.936
malicious
URL
Details
Close
https://site-3da5qr19c.godaddysites.com
malicious
SHA256:
VMRay Threat Identifiers
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
4/5
Phishing page detected via Machine Learning
2/5
Page is served from a service commonly used for temporary hosting
2/5
Page title matches the name of a popular online service
1/5
Page secured via a Domain Validated SSL certificate
1/5
Logon form detected via Computer Vision
1/5
Content matched by YARA rules
1/5
Resource is loaded from a service commonly used for temporary hosting
Full Report
Close
Phishing
Full Report
http://site-3da5qr19c.godaddysites.com
2026-08-23T20:15:16.539
malicious
URL
Details
Close
http://site-3da5qr19c.godaddysites.com
malicious
SHA256:
VMRay Threat Identifiers
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
4/5
Phishing page detected via Machine Learning
2/5
Page is served from a service commonly used for temporary hosting
2/5
Page title matches the name of a popular online service
1/5
Page secured via a Domain Validated SSL certificate
1/5
Logon form detected via Computer Vision
1/5
Content matched by YARA rules
1/5
Resource is loaded from a service commonly used for temporary hosting
Full Report
Close
Phishing
Full Report
152C07C2BAE3DDD5A3CBE3D8D65F335B.dll
2026-08-23T20:06:49.231
malicious
Windows DLL (x86-32)
Details
Close
152C07C2BAE3DDD5A3CBE3D8D65F335B.dll
malicious
SHA256: aa342021227e16248745ea0ea2ca1058fbb7340b31fbed6224f298e12df0a1b2
VMRay Threat Identifiers
Severity
Operation
5/5
ValleyRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Classifies external IP address
3/5
Suspicious content matched by YARA rules
2/5
Suspicious content matched by YARA rules
2/5
Signed executable failed signature validation
2/5
Delays execution
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Creates a page with write and execute permissions
1/5
Writes an unusually large amount of data to the registry
1/5
Query OS Information
1/5
Collects hardware properties
1/5
Enumerates running processes
1/5
Connects to remote host
1/5
Creates mutex
Full Report
Close
Backdoor
Full Report
e236b29c4949effad645c083010711a1fb976ef28fb12e70add960651cb9ff2f.dll
2026-08-23T19:32:56.641
malicious
Windows DLL (x86-64)
Details
Close
e236b29c4949effad645c083010711a1fb976ef28fb12e70add960651cb9ff2f.dll
malicious
SHA256: e236b29c4949effad645c083010711a1fb976ef28fb12e70add960651cb9ff2f
VMRay Threat Identifiers
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Tries to evade debugger
3/5
Uses HTTP to upload a large amount of data
2/5
Tries to detect virtual machine
2/5
Signed executable failed signature validation
2/5
Delays execution
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Tries to detect application sandbox
1/5
Content matched by YARA rules
Full Report
Close
Spyware
Full Report
4e722b2c7de02e199bda564c3727a8b48105fc1ad359a4e8a6a37705aacf42a3.dll
2026-08-23T19:30:29.142
malicious
Windows DLL (x86-64)
Details
Close
4e722b2c7de02e199bda564c3727a8b48105fc1ad359a4e8a6a37705aacf42a3.dll
malicious
SHA256: 4e722b2c7de02e199bda564c3727a8b48105fc1ad359a4e8a6a37705aacf42a3
VMRay Threat Identifiers
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Tries to evade debugger
2/5
Delays execution
2/5
Signed executable failed signature validation
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Unusual large memory allocation
1/5
Enumerates running processes
1/5
Tries to detect debugger
1/5
Tries to detect application sandbox
1/5
Content matched by YARA rules
Full Report
Close
Spyware
Full Report
1
2
520601
>