Threat Feed
DiscordZapret.exe
2026-09-14T17:39:51.424
malicious
Windows Exe (x86-32)
Close
DiscordZapret.exe
malicious
SHA256:
6b25bec5f70a99b15ca272363d6fae8f84aa9a5b19283b9e90623660b76c703a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
5/5
SalatStealer configuration was extracted
5/5
Known malicious mutex name is created
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
4/5
Creates a Process with redirected Input
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Searches for sensitive browser data
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Reads network adapter information
2/5
Delays execution
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Schedules task
1/5
Content matched by YARA rules
1/5
Creates process with hidden window
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
1/5
Possibly does reconnaissance
1/5
Enumerates running processes
1/5
Queries system time
1/5
Accesses Microsoft Security Software registry keys
1/5
Performs DNS request
1/5
Reads system data
Spyware
vps_beacon.exe
2026-09-14T17:38:07.596
malicious
Windows Exe (x86-64)
Close
vps_beacon.exe
malicious
SHA256:
477b5d2ae9f11b29856bf441b15f314a9cd5a5ddee5d1b1b9d72e143dc312b90
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Metasploit configuration was extracted
4/5
Malicious file detected via reputation
3/5
Tries to open an unusually high number of parallel network connections
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
Downloader
Hacktool
agent.exe
2026-09-14T17:22:39.360
malicious
Windows Exe (x86-64)
Close
agent.exe
malicious
SHA256:
b928bbab41b557aada3cc35539fef1f219e32afefdca9178e24c204b120b122e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
2/5
Delays execution
2/5
Sets up server that accepts incoming connections
2/5
Reads network adapter information
1/5
Tries to connect using an uncommon port
1/5
Resolves API functions dynamically
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Unusual large memory allocation
Hacktool
DiscordZapret.exe
2026-09-14T17:21:39.557
malicious
Windows Exe (x86-64)
Close
DiscordZapret.exe
malicious
SHA256:
c265f07f33a800f9a96bb20dfc0f677d5599ecd719304e29c30f579849b0a2f2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows configuration discovery
5/5
Known malicious mutex name is created
5/5
Tries to read cached credentials of various applications
5/5
SalatStealer configuration was extracted
4/5
Malicious file detected via reputation
4/5
Creates a Process with redirected Input
3/5
Takes screenshot
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Schedules task
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
1/5
Possibly does reconnaissance
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Unusual large memory allocation
1/5
Reads system data
1/5
Creates process with hidden window
1/5
Queries system time
1/5
Monitors keyboard input
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Monitors mouse movements and clicks
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Modifies application directory
1/5
Accesses volumes directly
Spyware
beacon.exe
2026-09-14T17:20:44.314
malicious
Windows Exe (x86-64)
Close
beacon.exe
malicious
SHA256:
0104d56f6608d319a9e148f6d77926fb41a37b7dd3dede9262f396c6b8e67176
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads the Security Account Manager (SAM) file
3/5
All network connection attempts failed
2/5
Delays execution
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
1/5
Unusual large memory allocation
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Connects to remote host
Spyware