Threat Feed
SecuriteInfo.com.Generic.Dacic.21301.158E32FB.93641826.exe
2026-08-20T20:31:12.988
malicious
Windows Exe (x86-64)
Close
SecuriteInfo.com.Generic.Dacic.21301.158E32FB.93641826.exe
malicious
SHA256:
ad821edb933557752728e1c68d3feb55258c99bb2c544e7a189c580ffe1bb546
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Tries to evade debugger
3/5
Uses HTTP to upload a large amount of data
3/5
Reads installed applications
2/5
Dead Drop Resolver
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Signed executable failed signature validation
2/5
Schedules task
1/5
Resolves API functions dynamically
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
1/5
Query CPU Properties
1/5
Query OS Information
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Queries system time
1/5
Creates mutex
Spyware
Injector
libwinpthread-1.dll
2026-08-20T19:52:24.126
malicious
Windows DLL (x86-64)
Close
libwinpthread-1.dll
malicious
SHA256:
0db0571c24997deae85af1e701c41cb44f83446f438ec8e2f82e0d1ba7c740fa
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Process Hollowing
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
3/5
Executes code with kernel privileges
2/5
Sends control codes to a driver
1/5
Queries system time
1/5
Creates mutex
1/5
Tries to detect debugger
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
1/5
Modifies operating system directory
1/5
Drops PE file
1/5
Installs system service
1/5
Content matched by YARA rules
1/5
Installs kernel driver
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
Injector
UTODYIBG.msi
2026-08-20T19:46:12.202
malicious
MSI Setup
Close
UTODYIBG.msi
malicious
SHA256:
f3d69fda955e715bb7ebc418db1e8a21bc5a8e05f38beb879c55087c7e21efb2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
DLL Hollowing
2/5
Queries a host's domain name
2/5
Suspicious content matched by YARA rules
2/5
Delays execution
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Signed executable failed signature validation
2/5
Schedules task
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Modifies operating system directory
1/5
Timestamp manipulation
1/5
A monitored process crashed
1/5
Installs system startup script or application
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Reloads native system libraries
1/5
Content matched by YARA rules
1/5
Executes dropped PE file
Downloader
Injector
https://bn.pb3.duckdns.org
2026-08-20T19:43:13.434
malicious
URL
Close
https://bn.pb3.duckdns.org
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
2/5
Page uses an invalid certificate
2/5
Performs DNS request for known DDNS domain
1/5
Page presents itself as a logon page
1/5
Logon form detected via Computer Vision
Phishing
https://cz.pb3.duckdns.org
2026-08-20T19:42:00.739
malicious
URL
Close
https://cz.pb3.duckdns.org
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
2/5
Page uses an invalid certificate
2/5
Performs DNS request for known DDNS domain
1/5
Page presents itself as a logon page
1/5
Logon form detected via Computer Vision
Phishing