Threat Feed
uDKUIMFA8VYSub92.exe
2026-09-05T03:51:37.226
malicious
Windows Exe (x86-32)
Close
uDKUIMFA8VYSub92.exe
malicious
SHA256:
b09de4578e7073a3c355b7405f6316ab25658575daef02b913de6cdabb488446
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
2/5
Allows invalid SSL certificates
2/5
Enables critical process privileges
1/5
Installs system service
1/5
Performs DNS request
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Modifies operating system directory
1/5
Enables process privileges
1/5
Creates mutex
1/5
Enumerates running processes
Ransomware
QuQHgKKRRvU2wnSM.exe
2026-09-05T03:50:18.403
malicious
Windows Exe (x86-64)
Close
QuQHgKKRRvU2wnSM.exe
malicious
SHA256:
51e9e140784e5ce96a59973d4cf360dbe727869c7832389192063ac21f4c85d1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Overwrites code
1/5
A monitored process crashed
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Modifies application directory
Ransomware
UsXKqphJzfHgMedA.exe
2026-09-05T03:46:23.184
malicious
Windows Exe (x86-64)
Close
UsXKqphJzfHgMedA.exe
malicious
SHA256:
c7566dac4f0264546912d46d37e5a3b1882741b6f5f5b690ef23bd9c6f17310e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Reads network adapter information
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Starts web browser in headless mode
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Tries to detect virtual machine
2/5
Delays execution
1/5
Reads from memory of another process
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Reloads native system libraries
1/5
Unusual large memory allocation
Spyware
Injector
hAeefdCvtfs8fb1a.exe
2026-09-05T03:46:22.343
malicious
Windows Exe (x86-32)
Close
hAeefdCvtfs8fb1a.exe
malicious
SHA256:
7e7686e658fb1bccbb810308557fd6318fe19286c6cb0b8b8db4bf47ddb44271
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
5/5
Modifies Windows automatic backups
4/5
Malicious content matched by YARA rules
4/5
Writes into the memory of another process
4/5
Bypasses Windows User Account Control (UAC)
4/5
Modifies Windows Update configuration
4/5
Tries to disable antivirus software
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Disables a crucial system tool
3/5
Modifies system configuration
3/5
Takes screenshot
3/5
Monitors keyboard input
3/5
Tries to evade debugger
3/5
Suspicious content matched by YARA rules
3/5
Captures clipboard data
3/5
Injects a file into another process
3/5
Disables a crucial system service
2/5
Tries to detect analyzer sandbox
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Changes the desktop wallpaper
2/5
Searches for sensitive FTP data
2/5
Hides files
2/5
Modifies network configuration
2/5
Creates an unusually large number of processes
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
2/5
Searches for sensitive browser data
2/5
Query OS Information
2/5
Network configuration discovery
2/5
Searches for cryptocurrency wallet locations
2/5
Queries a host's domain name
2/5
Collects hardware properties
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Executes WMI query
1/5
Reads from memory of another process
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Modifies operating system directory
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Monitors keyboard input
1/5
Enables process privileges
Spyware
Ransomware
Injector
apX161KIpDtwg26u.exe
2026-09-05T03:44:53.154
malicious
Windows Exe (x86-64)
Close
apX161KIpDtwg26u.exe
malicious
SHA256:
ae71e5f6886334e4dfd1f05fe4b534c51c32f8c067e8eaca62613296b3c0cc4f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
Modifies application directory
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Possibly does reconnaissance
Ransomware