Threat Feed
ZgyUWouXq0WYdjZJ.html
2026-08-10T07:10:56.531
malicious
HTML Document
Close
ZgyUWouXq0WYdjZJ.html
malicious
SHA256:
11338287333fe6bdcd5df17bcad2c0670fd558c08cef8104751110f847001341
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
tJ9OcGGqy6WjkddE.exe
2026-08-10T07:04:19.921
malicious
Windows Exe (x86-32)
Close
tJ9OcGGqy6WjkddE.exe
malicious
SHA256:
f4ac4f735b9ff260a275734d86610dccb8558d1a54c6d6a78a94c33b6aaf6e39
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
The binary file was created with a packer
Bot
https://allegrolokalnie.dn-produkt0168915.lat/logowanie?referrer=http://allegrolokalnie.dn-produkt0168915.lat/kukirin-g4-2026r/34747/wiadomosci/
2026-08-10T06:15:17.411
malicious
URL
Close
https://allegrolokalnie.dn-produkt0168915.lat/logowanie?referrer=http://allegrolokalnie.dn-produkt0168915.lat/kukirin-g4-2026r/34747/wiadomosci/
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
4/5
Malicious host or URL detected via reputation
2/5
Page is hosted on a recently registered domain
1/5
Page uses exact favicon of a popular online service
1/5
Page presents itself as a logon page
1/5
Page secured via a Domain Validated SSL certificate
1/5
Logon form detected via Computer Vision
Phishing
SOA_CD105474 _ TF912Z P10406 MGR-08-10....Pdf.JS
2026-08-10T06:07:37.231
malicious
JScript
Close
SOA_CD105474 _ TF912Z P10406 MGR-08-10....Pdf.JS
malicious
SHA256:
cefd48d22cae93ae7116f8f731fdc245b19191e56944672cd04918374b5eb8fc
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Sets up server that accepts incoming connections
5/5
Agent Tesla configuration was extracted
5/5
Combination of other detections shows configuration discovery
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
4/5
Tries to detect application sandbox
4/5
Malicious host or URL detected via reputation
3/5
Reads sensitive browser data
3/5
Reads sensitive mail data
3/5
Suspicious content matched by YARA rules
3/5
Suspicious file detected via reputation
3/5
Classifies external IP address
2/5
Tries to connect using an uncommon port
2/5
Reads network adapter information
2/5
Searches for sensitive mail data
2/5
Searches for sensitive browser data
2/5
Performs DNS request
2/5
Suspicious content matched by YARA rules
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Enables process privileges
2/5
Possibly does reconnaissance
2/5
Executes dropped PE file
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Connects to remote host
1/5
Unusual large memory allocation
1/5
Queries system time
Spyware
Backdoor
Downloader
xgvJfejdmrokDsnw.exe
2026-08-10T06:00:17.933
malicious
Windows Exe (x86-32)
Close
xgvJfejdmrokDsnw.exe
malicious
SHA256:
e461fe7cc6c7bb37c25278678e1cd683fbe29e494a8882bb8ed7c8a212112c92
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Process Hollowing
4/5
Writes into the memory of another process
3/5
Monitors user input
2/5
Searches for sensitive application data
2/5
Reads sensitive mail data
2/5
Searches for sensitive browser data
2/5
Delays execution
2/5
Creates an unusually large number of processes
2/5
Searches for sensitive mail data
2/5
Deletes file after execution
2/5
Schedules task
1/5
Drops PE file
1/5
Tries to detect debugger
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Enumerates running processes
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Reads from memory of another process
1/5
Enables process privileges
1/5
Reads mouse position
1/5
Monitors mouse movements and clicks
1/5
Possibly does reconnaissance
1/5
Executes WMI query
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
Injector