Threat Feed
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com%2F&%3Bifkv=AQMjQ7QyROPzn0qaqnYvX4_aw7qH8RajahyDV4UI8mo2Mw7SaNi-z6QQG4MH4pDlzJ2gDPTt_nm2&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SQ9W9iLOE4pyI2qhkS-m2IH4LmnirIYBWH3_BygAvuaGZN1G6TuCwrh2YSySqhwf7HDzIf2&dsh=S1494803030%3A1790197658060536
2026-09-23T21:41:20.107
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com%2F&%3Bifkv=AQMjQ7QyROPzn0qaqnYvX4_aw7qH8RajahyDV4UI8mo2Mw7SaNi-z6QQG4MH4pDlzJ2gDPTt_nm2&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SQ9W9iLOE4pyI2qhkS-m2IH4LmnirIYBWH3_BygAvuaGZN1G6TuCwrh2YSySqhwf7HDzIf2&dsh=S1494803030%3A1790197658060536
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Branded Logon form detected via Computer Vision
2/5
Page uses exact same title as that of a popular online service
1/5
HTTPS page insecurely loads resources via HTTP
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
CGYhRbdBDKoaMWJs.exe
2026-09-23T21:25:25.677
malicious
Windows Exe (x86-32)
Close
CGYhRbdBDKoaMWJs.exe
malicious
SHA256:
e7c842febd9ae4d7011be22c84134c65d362337acd4addb084aff4fdf01780e2
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Schedules task
2/5
Delays execution
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Unusual large memory allocation
Injector
ICB19o9GmL4PeOkc.exe
2026-09-23T21:25:10.287
malicious
Windows Exe (x86-64)
Close
ICB19o9GmL4PeOkc.exe
malicious
SHA256:
01ba424a2b0f8be9b4a31a1b365eded53426f8cda91ef381c1aa1f198a187f2a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads a significant portion of browser memory
4/5
Malicious file detected via reputation
4/5
Creates elevated child process
2/5
Schedules task
2/5
Sends control codes to a driver
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Possibly does reconnaissance
gznFMK94iskjVkad.exe
2026-09-23T21:24:30.683
malicious
Windows Exe (x86-64)
Close
gznFMK94iskjVkad.exe
malicious
SHA256:
4b14d5695a553aacf990bb6ad0bca2dd5ca5142e38903ad52d2c7d4e639751d8
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
4/5
Malicious file detected via reputation
3/5
Tries to detect the presence of antivirus software
3/5
Uses HTTP to upload a large amount of data
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Collects hardware properties
2/5
Collects BIOS properties
2/5
Searches for sensitive browser data
2/5
Accesses physical drive
2/5
Reads network adapter information
2/5
Reads installed applications
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Query OS Information
1/5
Queries system time
1/5
Accesses volumes directly
1/5
Enumerates running processes
1/5
Reads system data
1/5
Tries to connect using an uncommon port
1/5
Checks external IP address
1/5
Executes WMI query
OkUxDE44ciCLLUfd.exe
2026-09-23T21:24:17.616
malicious
Windows Exe (x86-32)
Close
OkUxDE44ciCLLUfd.exe
malicious
SHA256:
41679f6b59dd7a5292e26314cd9d8da40f9f6e71dfa427ce47644f5b407ef529
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Schedules task
2/5
Delays execution
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Unusual large memory allocation
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
Injector