Threat Feed
3ea2740322db4a5c4066ef2f09618937eda3f10717fde2ba2df76b6c4da81aa7.exe
2026-09-27T21:15:50.761
malicious
Windows Exe (x86-32)
Close
3ea2740322db4a5c4066ef2f09618937eda3f10717fde2ba2df76b6c4da81aa7.exe
malicious
SHA256:
3ea2740322db4a5c4066ef2f09618937eda3f10717fde2ba2df76b6c4da81aa7
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Delays execution
2/5
Queries a host's domain name
1/5
Enables process privileges
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
Backdoor
1987abcfd3a4c0b0929d2c2295255543eeacd2fe641b47e065f30d59efbbd5db.exe
2026-09-27T21:15:31.567
malicious
Windows Exe (x86-64)
Close
1987abcfd3a4c0b0929d2c2295255543eeacd2fe641b47e065f30d59efbbd5db.exe
malicious
SHA256:
1987abcfd3a4c0b0929d2c2295255543eeacd2fe641b47e065f30d59efbbd5db
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Reads network adapter information
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor
e90612572911324615788f50df787658e32e6f81da2830564caf8172c70f34d9.exe
2026-09-27T21:15:31.104
malicious
Windows Exe (x86-64)
Close
e90612572911324615788f50df787658e32e6f81da2830564caf8172c70f34d9.exe
malicious
SHA256:
e90612572911324615788f50df787658e32e6f81da2830564caf8172c70f34d9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Reads network adapter information
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor
Downloader
266b26ffb579cdc406fd1db02d20adbd.exe
2026-09-27T20:53:59.342
malicious
Windows Exe (x86-32)
Close
266b26ffb579cdc406fd1db02d20adbd.exe
malicious
SHA256:
fa0104544c2a72a4d7f62297ab0c23146b9d793af0d2c9c32f0c71d4ddeffaa9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
5/5
NanoCore configuration was extracted
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Obscures a file's origin
3/5
Monitors user input
2/5
Sets up server that accepts incoming connections
1/5
Installs system startup script or application
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Reads system data
1/5
Query OS Information
1/5
Modifies application directory
1/5
Performs DNS request
1/5
Connects to remote host
Spyware
Backdoor
bot.amd64
2026-09-27T20:52:53.630
malicious
Linux ELF Executable (x86-64)
Close
bot.amd64
malicious
SHA256:
2ee79ef8b3c3edc2ae1a5351e940cf3022db39d677e6870d63cdfe4234b6b437
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Connects to multiple remote hosts
3/5
Installs system startup script or application
3/5
Tries to detect the presence of antivirus software
2/5
Creates an unusually large number of processes
2/5
Delays execution
2/5
Deletes logs
2/5
Sets up server that accepts incoming connections
2/5
Enumerates running processes
2/5
Schedules task with Cron
1/5
Drops ELF file
1/5
Clones process
1/5
Creates hidden file or folder
1/5
Tries to connect using an uncommon port
1/5
Connects to remote host
Bot