Threat Feed
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com%2F&%3Bifkv=ASKXGp36_CB8HzfrpuLLHTVjXxiUGDwO6Tj8yz4QrsaGyc3I4H4G7NxTTQJtpw0j07g9O5T5Tx4uyQ&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SS5Rm_txFQWsJNEsqu78mnD_pq0c0BYjHMdhUNyS96qdC5K7boxcTGVuOIlfgvRmfgP_k2_qQ&dsh=S1443696563%3A1791234036737603
2026-10-05T21:27:20.989
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com%2F&%3Bifkv=ASKXGp36_CB8HzfrpuLLHTVjXxiUGDwO6Tj8yz4QrsaGyc3I4H4G7NxTTQJtpw0j07g9O5T5Tx4uyQ&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SS5Rm_txFQWsJNEsqu78mnD_pq0c0BYjHMdhUNyS96qdC5K7boxcTGVuOIlfgvRmfgP_k2_qQ&dsh=S1443696563%3A1791234036737603
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Page uses exact same title as that of a popular online service
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
1/5
HTTPS page insecurely loads resources via HTTP
Phishing
sYPkQvN6oi8hQIFE.exe
2026-10-05T21:26:08.428
malicious
Windows Exe (x86-32)
Close
sYPkQvN6oi8hQIFE.exe
malicious
SHA256:
68a412ec90fb9846af159ed75bbae1dc1118669ff263b48c226c878c15f39ce3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read default login credentials
4/5
Malicious file detected via reputation
2/5
Searches for sensitive mail data
2/5
Searches for sensitive application data
2/5
Reads network adapter information
2/5
Searches for sensitive browser data
2/5
Searches for sensitive developer application configuration data
2/5
Searches for sensitive FTP data
2/5
Network configuration discovery
2/5
Reads sensitive browser data
2/5
Creates an unusually large number of processes
2/5
Executes PowerShell without default profile
2/5
Queries a host's domain name
1/5
Executes WMI query
1/5
Possibly does reconnaissance
1/5
Content matched by YARA rules
1/5
Creates process with hidden window
1/5
Resolves API functions dynamically
1/5
Accesses volumes directly
1/5
Unusual large memory allocation
LXBVWxfCf494UvCe.exe
2026-10-05T21:25:11.573
malicious
Windows Exe (x86-64)
Close
LXBVWxfCf494UvCe.exe
malicious
SHA256:
e656ce6fd1b8cd69c7236b6db7261ad7aa06461afe932149eaef2799a4110596
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Tries to detect the presence of antivirus software
2/5
Query Firmware Information
2/5
Queries a host's domain name
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Makes direct system call to possibly evade hooking based monitoring
1/5
Overwrites code
1/5
Unusual large memory allocation
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Resolves API functions dynamically
1/5
Tries to detect application sandbox
1/5
Query OS Information
Spyware
h4ZQrPbLYccNKFNv.exe
2026-10-05T21:25:07.696
malicious
Windows Exe (x86-64)
Close
h4ZQrPbLYccNKFNv.exe
malicious
SHA256:
de0f6949e2de92aaae6beb795bc58bd77ff122175ac3edc5b94b03830f0036f0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious file detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Tries to open an unusually high number of parallel network connections
3/5
Uses HTTP to upload a large amount of data
2/5
Signed executable failed signature validation
2/5
Tries to detect analyzer sandbox
2/5
Delays execution
1/5
Content matched by YARA rules
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
Spyware
Vxrwl2kpuA9UCyK9.exe
2026-10-05T21:23:00.764
malicious
Windows Exe (x86-32)
Close
Vxrwl2kpuA9UCyK9.exe
malicious
SHA256:
face753e385b8f374e030b49a033ae56c0dd03326fc2bfdece573dc10e2da138
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
3/5
Takes screenshot
3/5
Uses HTTP to upload a large amount of data
2/5
Reads sensitive browser data
2/5
Reads network adapter information
2/5
Tries to detect virtual machine
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Tries to detect debugger
1/5
Queries system time
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Content matched by YARA rules
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Creates a page with write and execute permissions
1/5
Accesses volumes directly
Spyware