Threat Feed
735CDA5521FE8B13168A40DA6BBE2036.exe
2026-08-26T03:14:35.163
malicious
Windows Exe (x86-32)
Close
735CDA5521FE8B13168A40DA6BBE2036.exe
malicious
SHA256:
a70a66a4530d9913f65f5d40945e03a2441ac077c62edc1b4e3f4343555c6943
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
5/5
Combination of other detections shows configuration discovery
4/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Sends data via a Telegram bot
3/5
Monitors keyboard input
3/5
Tries to detect the presence of firewall software
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
2/5
Collects BIOS properties
2/5
Collects hardware properties
2/5
Searches for sensitive application data
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Modifies network configuration
2/5
Searches for cryptocurrency wallet locations
2/5
Enumerates running processes
2/5
Schedules task
1/5
Accesses Microsoft Security Software registry keys
1/5
Connects to remote host
1/5
Modifies operating system directory
1/5
Content matched by YARA rules
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Writes an unusually large amount of data to the registry
1/5
Queries system time
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Modifies application directory
1/5
Reads from memory of another process
1/5
Installs system startup script or application
1/5
Performs DNS request
1/5
Query OS Information
Spyware
Backdoor
6074FB302F3BCCC8ED02678BE6588F6F.exe
2026-08-26T03:14:21.969
malicious
Windows Exe (x86-32)
Close
6074FB302F3BCCC8ED02678BE6588F6F.exe
malicious
SHA256:
736daa65bb88e35cac8c90385140722da1b074032f4de319a0e2682ceb6f0aa5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
ValleyRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Schedules task
2/5
Enables critical process privileges
2/5
Delays execution
2/5
Signed executable failed signature validation
1/5
Writes an unusually large amount of data to the registry
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Queries system time
1/5
Collects hardware properties
1/5
Enables process privileges
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Creates mutex
Backdoor
fc02692a98927272e200e01eb80007cc03aedbdec8acfb68aa9730dabaa8fce1.exe
2026-08-26T01:52:54.573
malicious
Windows Exe (x86-64)
Close
fc02692a98927272e200e01eb80007cc03aedbdec8acfb68aa9730dabaa8fce1.exe
malicious
SHA256:
cc6e4b971695ce08fb2dae289e148b95e09cd3b807ab242fede1f0a347f2f598
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious host or URL detected via reputation
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Tries to detect virtual machine
2/5
Dead Drop Resolver
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Creates mutex
1/5
Tries to detect application sandbox
1/5
Queries system time
1/5
Query CPU Properties
1/5
Resolves API functions dynamically
Spyware
99BPqTee2gi7PHl4.exe
2026-08-26T01:08:58.240
malicious
Windows Exe (x86-64)
Close
99BPqTee2gi7PHl4.exe
malicious
SHA256:
d9b374340f0bb6b80587b4ba0bf1a5ddbd8d0e18cd153f3e773a542d97a2f375
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Reads installed applications
2/5
Signed executable failed signature validation
2/5
Schedules task
2/5
Searches for cryptocurrency wallet locations
2/5
Dead Drop Resolver
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
1/5
Creates a page with write and execute permissions
1/5
Installs system startup script or application
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Query CPU Properties
1/5
Query OS Information
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Overwrites code
Spyware
HHNvoyhtmWCiXtbQ.exe
2026-08-26T01:07:01.680
malicious
Windows Exe (x86-64)
Close
HHNvoyhtmWCiXtbQ.exe
malicious
SHA256:
fc02692a98927272e200e01eb80007cc03aedbdec8acfb68aa9730dabaa8fce1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious content matched by YARA rules
3/5
Tries to open an unusually high number of parallel network connections
3/5
Uses HTTP to upload a large amount of data
2/5
Delays execution
2/5
Tries to detect analyzer sandbox
1/5
Queries system time
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Creates mutex
Spyware