Threat Feed
M6SOohKQqKjDioJZ.html
2026-07-30T19:03:26.130
malicious
HTML Document
Close
M6SOohKQqKjDioJZ.html
malicious
SHA256:
326494877cfd8e23c6ad1aede24d3e62ef7bbac6dd910bdffff55260db6a751a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
file.exe
2026-07-30T18:48:51.725
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
c05581c54fb2e63ab1b6d0c8957d24fbcbc0e094339bc02838b50b3f72dddeff
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
5/5
Combination of other detections shows multiple input capture behaviors
3/5
Captures clipboard data
3/5
Reads installed applications
3/5
Takes screenshot
2/5
Suspicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Searches for sensitive browser data
2/5
Sets up server that accepts incoming connections
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Query OS Information
1/5
Timestamp manipulation
1/5
Enables process privileges
1/5
Queries system time
1/5
Enumerates running processes
1/5
Accesses volumes directly
1/5
Creates process with hidden window
1/5
Kills process
1/5
Reads from memory of another process
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Loads a dropped DLL
Spyware
SecuriteInfo.com.Win32.MalwareX-gen.81626146.exe
2026-07-30T18:38:49.628
malicious
Windows Exe (x86-32)
Close
SecuriteInfo.com.Win32.MalwareX-gen.81626146.exe
malicious
SHA256:
3e1b1fe0edaa2aa1cd743646f41354eaaf7eaf54d47a416f141ba9f9320024fd
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Writes into the memory of another process
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Malicious host or URL detected via reputation
4/5
Process Hollowing
3/5
Suspicious host or URL detected via reputation
3/5
Captures clipboard data
2/5
Delays execution
2/5
Tries to detect kernel debugger
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Creates a page with write and execute permissions
1/5
Accesses Microsoft Security Software registry keys
1/5
Query OS Information
1/5
Enables process privileges
1/5
Reads from memory of another process
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Tries to detect debugger
Spyware
Injector
QuickFetch.exe
2026-07-30T17:01:39.715
malicious
Windows Exe (x86-64)
Close
QuickFetch.exe
malicious
SHA256:
49b46e61efe06551f1d58edf4b33d275f32aab64978a826d4620f5340ac6fc2a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Uses HTTP to upload a large amount of data
3/5
Tries to detect the presence of antivirus software
3/5
Captures clipboard data
3/5
Takes screenshot
2/5
Queries a host's domain name
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Delays execution
2/5
Suspicious content matched by YARA rules
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Query Firmware Information
1/5
Tries to connect using an uncommon port
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
Spyware
ZapretX.exe
2026-07-30T16:50:14.818
malicious
Windows Exe (x86-32)
Close
ZapretX.exe
malicious
SHA256:
537dea2679e48b347b6bc905d2eb17b4dde6855cf82bcea4ec5486f2c221346f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
5/5
Known malicious mutex name is created
5/5
SalatStealer configuration was extracted
5/5
Combination of other detections shows configuration discovery
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Searches for sensitive browser data
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Delays execution
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Schedules task
1/5
Reads system data
1/5
Content matched by YARA rules
1/5
Modifies application directory
1/5
Possibly does reconnaissance
1/5
Resolves API functions dynamically
1/5
Enumerates running processes
1/5
A monitored process crashed
1/5
Creates process with hidden window
1/5
Queries system time
1/5
Unusual large memory allocation
1/5
Accesses Microsoft Security Software registry keys
1/5
Performs DNS request
Spyware