Threat Feed
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AeYxHgf51DUbhmwWvVFHK1W71914Fak2N_EujevzlosJb4y8fik3j8GxEk4yNLPhfCySiHi13NiivA&dsh=S2097209227%3A1788495794660376
2026-09-04T05:45:24.014
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AeYxHgf51DUbhmwWvVFHK1W71914Fak2N_EujevzlosJb4y8fik3j8GxEk4yNLPhfCySiHi13NiivA&dsh=S2097209227%3A1788495794660376
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Page uses exact same title as that of a popular online service
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Content matched by YARA rules
1/5
Page presents itself as a logon page
1/5
HTTPS page insecurely loads resources via HTTP
Phishing
VTC7Hg1PBSjj4ysv.exe
2026-09-04T05:40:56.260
malicious
Windows Exe (x86-32)
Close
VTC7Hg1PBSjj4ysv.exe
malicious
SHA256:
c7cdcfd85ea0d3c52276dffdbcd47cbd37f1787d7ac7eaeb7c5fa643d6f6fc72
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Modifies Windows automatic backups
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Tries to disable antivirus software
4/5
Malicious content matched by YARA rules
4/5
Blocks network connection to security products
4/5
Writes into the memory of another process
4/5
Disables a crucial system tool
4/5
Bypasses Windows User Account Control (UAC)
3/5
Injects a file into another process
3/5
Disables a crucial system service
3/5
Monitors keyboard input
3/5
Suspicious content matched by YARA rules
3/5
Captures clipboard data
3/5
Takes screenshot
2/5
Hides files
2/5
Searches for sensitive remote access configuration data
2/5
Sets up server that accepts incoming connections
2/5
Masquerades file extension
2/5
Searches for sensitive password manager data
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell with hidden window
2/5
Executes PowerShell without default profile
2/5
Schedules task
2/5
Locks the Windows desktop
2/5
Searches for sensitive browser data
2/5
Query OS Information
2/5
Changes the desktop wallpaper
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Query OS Information
1/5
Modifies operating system directory
1/5
Creates process with hidden window
1/5
Monitors keyboard input
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Enables process privileges
1/5
Accesses Microsoft Security Software registry keys
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Creates mutex
1/5
Resolves API functions dynamically
Spyware
Ransomware
Injector
Cy3qNpN1AjUoHzAf.exe
2026-09-04T05:40:06.527
malicious
Windows Exe (x86-64)
Close
Cy3qNpN1AjUoHzAf.exe
malicious
SHA256:
196062d07f3afc725e4dc80ac7c41b4ebaf7be58aeaf3c8971afe9924c6cb2a6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
XMRig configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Executes code with kernel privileges
3/5
Tries to open an unusually high number of parallel network connections
3/5
Suspicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Deletes file after execution
2/5
Sends control codes to a driver
2/5
Reads network adapter information
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
2/5
Schedules task
1/5
Modifies operating system directory
1/5
Installs kernel driver
1/5
Resolves API functions dynamically
1/5
Enumerates running processes
1/5
A monitored process crashed
1/5
Enables process privileges
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Unusual large memory allocation
1/5
Drops PE file
1/5
Installs system service
1/5
Tries to detect application sandbox
1/5
Executes dropped PE file
1/5
Possibly does reconnaissance
1/5
Content matched by YARA rules
PUA
Miner
nsD1xWiS0qefXR5Y.exe
2026-09-04T05:37:58.693
malicious
Windows Exe (x86-32)
Close
nsD1xWiS0qefXR5Y.exe
malicious
SHA256:
03295720717c1d05c60fefdc7a2018a483699fdc9c6e3a774c108cd6549529c3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
4/5
Uses a double file extension
2/5
Modifies network configuration
2/5
Sets up server that accepts incoming connections
2/5
Connects to SMTP server
1/5
Queries system time
1/5
Content matched by YARA rules
1/5
Drops PE file
1/5
Drops PE masquerading Filename
1/5
Connects to remote host
1/5
Creates mutex
1/5
Modifies application directory
1/5
Modifies operating system directory
1/5
Installs system startup script or application
1/5
Enumerates running processes
1/5
Performs DNS request
Worm
tJdi53LPwWl92Q9u.exe
2026-09-04T05:37:10.112
malicious
Windows Exe (x86-32)
Close
tJdi53LPwWl92Q9u.exe
malicious
SHA256:
943e063d6fd931e84ca266ccde19b2d41f320e0d9d2638f3702bbef88c8899eb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
All network connection attempts failed
3/5
Deletes file after execution
2/5
Delays execution
2/5
Deletes file after execution
1/5
Installs system startup script or application
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Creates process with hidden window
1/5
Queries system time
Backdoor