{"id":127,"date":"2026-05-29T03:27:04","date_gmt":"2026-05-29T03:27:04","guid":{"rendered":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/"},"modified":"2026-05-29T03:27:04","modified_gmt":"2026-05-29T03:27:04","slug":"threatinfo-daily-digest-2026-05-29","status":"publish","type":"post","link":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/","title":{"rendered":"ThreatInfo Detection Digest: May 29, 2026"},"content":{"rendered":"<section class=\"ti-digest-brief\">\n<p class=\"ti-digest-kicker\">ThreatInfo research digest<\/p>\n<p class=\"ti-digest-lead\">A concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.<\/p>\n<div class=\"ti-digest-summary\">\n<div><span>New report links<\/span><strong>13<\/strong><\/div>\n<div><span>Tracked categories<\/span><strong>5<\/strong><\/div>\n<div><span>Primary action<\/span><strong>Verify hash<\/strong><\/div>\n<\/div>\n<\/section>\n<section class=\"ti-digest-map\">\n<h2>Category overview<\/h2>\n<div class=\"ti-digest-watchlist\"><a href=\"https:\/\/threatinfo.net\/categories\/adware\"><strong>Adware<\/strong><span>4 new reports<\/span><\/a><a href=\"https:\/\/threatinfo.net\/categories\/pup\"><strong>PUP\/PUA<\/strong><span>2 new reports<\/span><\/a><a href=\"https:\/\/threatinfo.net\/categories\/trojan\"><strong>Trojan<\/strong><span>4 new reports<\/span><\/a><a href=\"https:\/\/threatinfo.net\/categories\/ransom\"><strong>Ransomware<\/strong><span>3 new reports<\/span><\/a><a href=\"https:\/\/threatinfo.net\/categories\/virus\"><strong>Virus<\/strong><span>0 new reports<\/span><\/a><\/div>\n<\/section>\n<section class=\"ti-digest-reports\">\n<h2>Reports worth opening<\/h2>\n<div class=\"ti-digest-category\">\n<div class=\"ti-digest-category-head\">\n<h3>Adware<\/h3>\n<p>Review browser changes, bundled installers, extensions, and unexpected advertising behavior.<\/p>\n<\/div>\n<div class=\"ti-digest-table\">\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/Log.dll-fbfec94b4be3344424528bf1ba0e09f6\">Log.dll<\/a><\/div>\n<div><span>Detection<\/span><strong>Adware.Gen<\/strong><\/div>\n<div><span>MD5<\/span><code>fbfec94b4be3344424528bf1ba0e09f6<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/Log.dll-f9dabbde034c44a12af5789d4b2b77d3\">Log.dll<\/a><\/div>\n<div><span>Detection<\/span><strong>Adware.Gen<\/strong><\/div>\n<div><span>MD5<\/span><code>f9dabbde034c44a12af5789d4b2b77d3<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/WinSAP.dll.mal-82c5813b6c3346a2601c555517a9a115\">WinSAP.dll.mal<\/a><\/div>\n<div><span>Detection<\/span><strong>Adware.ELEX<\/strong><\/div>\n<div><span>MD5<\/span><code>82c5813b6c3346a2601c555517a9a115<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/A0019670.dll-b212865e7e478a28a97268f960079a8d\">A0019670.dll<\/a><\/div>\n<div><span>Detection<\/span><strong>PUP.Babylon<\/strong><\/div>\n<div><span>MD5<\/span><code>b212865e7e478a28a97268f960079a8d<\/code><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ti-digest-category\">\n<div class=\"ti-digest-category-head\">\n<h3>PUP\/PUA<\/h3>\n<p>Check whether the file came from an installer bundle, optimizer, updater, or optional offer.<\/p>\n<\/div>\n<div class=\"ti-digest-table\">\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/vSnapshotServ.exe%2396B0B71AFAFF3277-cc39b2015fd48ca82a8114146da966be\">vSnapshotServ.exe#96B0B71AFAFF3277<\/a><\/div>\n<div><span>Detection<\/span><strong>PUP.Gen<\/strong><\/div>\n<div><span>MD5<\/span><code>cc39b2015fd48ca82a8114146da966be<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/OnlineGuardian-v2.exe-3f2e8e25f44ce81aede2b5e5165b7166\">OnlineGuardian-v2.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>PUP.Gen<\/strong><\/div>\n<div><span>MD5<\/span><code>3f2e8e25f44ce81aede2b5e5165b7166<\/code><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ti-digest-category\">\n<div class=\"ti-digest-category-head\">\n<h3>Trojan<\/h3>\n<p>Verify the hash and origin before trusting the filename; trojans often imitate legitimate software.<\/p>\n<\/div>\n<div class=\"ti-digest-table\">\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/A0005624.exe-271fc11622cbbb3abfdc174e38b9b390\">A0005624.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>General Threat<\/strong><\/div>\n<div><span>MD5<\/span><code>271fc11622cbbb3abfdc174e38b9b390<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/vusbbus.sys-631cb85802785e004afa0194284d0786\">vusbbus.sys<\/a><\/div>\n<div><span>Detection<\/span><strong>Trojan.Agent<\/strong><\/div>\n<div><span>MD5<\/span><code>631cb85802785e004afa0194284d0786<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/tscitres.exe-ad5e6eb33f8b6b48fab6d9ab3e1212c1\">tscitres.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>Trojan.Autoit<\/strong><\/div>\n<div><span>MD5<\/span><code>ad5e6eb33f8b6b48fab6d9ab3e1212c1<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/rfagent64.exe-2f7aba8d94d5063a430d532d9066ab74\">rfagent64.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>PUP.Gen<\/strong><\/div>\n<div><span>MD5<\/span><code>2f7aba8d94d5063a430d532d9066ab74<\/code><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ti-digest-category\">\n<div class=\"ti-digest-category-head\">\n<h3>Ransomware<\/h3>\n<p>Prioritize isolation and backup checks when this class appears on an endpoint.<\/p>\n<\/div>\n<div class=\"ti-digest-table\">\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/updatewin1.exe-4a7f0327b2ea4fdd6e2c5d1f439094dc\">updatewin1.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>Trojan.Downloader<\/strong><\/div>\n<div><span>MD5<\/span><code>4a7f0327b2ea4fdd6e2c5d1f439094dc<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/csrss.exe-a59b6178979a69c35e1d97b7bba77fb2\">csrss.exe<\/a><\/div>\n<div><span>Detection<\/span><strong>Ransom.Wacatac<\/strong><\/div>\n<div><span>MD5<\/span><code>a59b6178979a69c35e1d97b7bba77fb2<\/code><\/div>\n<\/div>\n<div class=\"ti-digest-row\">\n<div><span>File<\/span><a href=\"https:\/\/threatinfo.net\/files\/main.exe.dat-aa126c647ff357f8798cd6e5762b55da\">main.exe.dat<\/a><\/div>\n<div><span>Detection<\/span><strong>Trojan.Agent<\/strong><\/div>\n<div><span>MD5<\/span><code>aa126c647ff357f8798cd6e5762b55da<\/code><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<section class=\"ti-digest-action\">\n<h2>How to use this digest<\/h2>\n<p>Start with the MD5 hash, not the filename. If the hash or file path matches a system you manage, open the report, review the publisher and detection details, then scan the endpoint with <a href=\"https:\/\/threatinfo.net\/download\">GridinSoft Anti-Malware<\/a>. ThreatInfo reports show whether GridinSoft already detects the file and which detection name is used.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>ThreatInfo research digest A concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"ThreatInfo Detection Digest: May 29, 2026\" class=\"read-more button\" href=\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#more-127\" aria-label=\"More on ThreatInfo Detection Digest: May 29, 2026\">Read more<\/a><\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":""},"categories":[50],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research<\/title>\n<meta name=\"description\" content=\"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research\" \/>\n<meta property=\"og:description\" content=\"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatInfo Research\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-29T03:27:04+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/threatinfo.net\/articles\/#website\",\"url\":\"https:\/\/threatinfo.net\/articles\/\",\"name\":\"ThreatInfo Research\",\"description\":\"Malware explainers, daily file-report links, hashes, GridinSoft detections, and remediation guidance from ThreatInfo Research\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/threatinfo.net\/articles\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#webpage\",\"url\":\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/\",\"name\":\"ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research\",\"isPartOf\":{\"@id\":\"https:\/\/threatinfo.net\/articles\/#website\"},\"datePublished\":\"2026-05-29T03:27:04+00:00\",\"dateModified\":\"2026-05-29T03:27:04+00:00\",\"author\":{\"@id\":\"\"},\"description\":\"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.\",\"breadcrumb\":{\"@id\":\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/threatinfo.net\/articles\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ThreatInfo Detection Digest: May 29, 2026\"}]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research","description":"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/","og_locale":"en_US","og_type":"article","og_title":"ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research","og_description":"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.","og_url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/","og_site_name":"ThreatInfo Research","article_published_time":"2026-05-29T03:27:04+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/threatinfo.net\/articles\/#website","url":"https:\/\/threatinfo.net\/articles\/","name":"ThreatInfo Research","description":"Malware explainers, daily file-report links, hashes, GridinSoft detections, and remediation guidance from ThreatInfo Research","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatinfo.net\/articles\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#webpage","url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/","name":"ThreatInfo Detection Digest: May 29, 2026 - ThreatInfo Research","isPartOf":{"@id":"https:\/\/threatinfo.net\/articles\/#website"},"datePublished":"2026-05-29T03:27:04+00:00","dateModified":"2026-05-29T03:27:04+00:00","author":{"@id":""},"description":"ThreatInfo detection digest with new file reports, malware categories, MD5 hashes, and GridinSoft verdict context.","breadcrumb":{"@id":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-29\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatinfo.net\/articles\/"},{"@type":"ListItem","position":2,"name":"ThreatInfo Detection Digest: May 29, 2026"}]}]}},"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":110,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-15\/","url_meta":{"origin":127,"position":0},"title":"ThreatInfo Detection Digest: May 15, 2026","date":"May 15, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":114,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-17\/","url_meta":{"origin":127,"position":1},"title":"ThreatInfo Detection Digest: May 17, 2026","date":"May 17, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":109,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-14\/","url_meta":{"origin":127,"position":2},"title":"ThreatInfo Detection Digest: May 14, 2026","date":"May 14, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":113,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-16\/","url_meta":{"origin":127,"position":3},"title":"ThreatInfo Detection Digest: May 16, 2026","date":"May 16, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":103,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-13\/","url_meta":{"origin":127,"position":4},"title":"ThreatInfo Detection Digest: May 13, 2026","date":"May 13, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":116,"url":"https:\/\/threatinfo.net\/articles\/threatinfo-daily-digest-2026-05-19\/","url_meta":{"origin":127,"position":5},"title":"ThreatInfo Detection Digest: May 19, 2026","date":"May 19, 2026","format":false,"excerpt":"ThreatInfo research digestA concise set of new file reports that were not used in recent digests. Each entry includes the detection name, MD5 hash, and a direct report link so analysts can verify the exact sample before taking action.New report links20Tracked categories5Primary actionVerify hashCategory overviewAdware4 new reportsPUP\/PUA4 new reportsTrojan4 new\u2026","rel":"","context":"In &quot;Daily Digest&quot;","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/posts\/127"}],"collection":[{"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/comments?post=127"}],"version-history":[{"count":0,"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/posts\/127\/revisions"}],"wp:attachment":[{"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/media?parent=127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/categories?post=127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatinfo.net\/articles\/wp-json\/wp\/v2\/tags?post=127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}