Threat Feed
Command line RAR.exe
2026-10-08T17:41:11.203
malicious
Windows Exe (x86-64)
Close
Command line RAR.exe
malicious
SHA256:
62618944ec9f6e7c1b6544f41bdc57da37b8c15eac33905b1c15e7b26e921d75
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
Creates a page with write and execute permissions
1/5
Modifies application directory
1/5
Resolves API functions dynamically
1/5
Queries system time
Ransomware
ok.exe
2026-10-08T17:36:44.503
malicious
Windows Exe (x86-64)
Close
ok.exe
malicious
SHA256:
f36a74d91a415ea9847eb7345bce9dcd0e7ee27d154be9e432a76eae5d02a7f0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Loads a known vulnerable file
4/5
Malicious content matched by YARA rules
3/5
Executes code with kernel privileges
3/5
Suspicious file detected via reputation
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
2/5
Sends control codes to a driver
2/5
Schedules task
1/5
Reads system data
1/5
Modifies operating system directory
1/5
Queries system time
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Enables process privileges
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
PUA
Miner
123.exe
2026-10-08T17:36:22.037
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
2bd3647167a50be04b88ff0530f4e47b86fb76b3c86b1c2f9ef157d39f5711c0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Loads a known vulnerable file
3/5
Executes code with kernel privileges
3/5
Suspicious file detected via reputation
2/5
Sets up server that accepts incoming connections
2/5
Creates an unusually large number of processes
2/5
Sends control codes to a driver
2/5
Reads network adapter information
1/5
Queries system time
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Enables process privileges
1/5
Reads system data
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
PUA
Miner
Qll6jAVxihku5iDj.exe
2026-10-08T17:36:17.506
malicious
Windows Exe (x86-32)
Close
Qll6jAVxihku5iDj.exe
malicious
SHA256:
717262b4e87efda068c35c6820473ac266d405e441a2e7d242d277ebefe3a872
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
5/5
SalatStealer configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Creates a Process with redirected Input
4/5
Malicious file detected via reputation
2/5
Collects hardware properties
2/5
Sets up server that accepts incoming connections
2/5
Queries OS info via WMI
2/5
Reads network adapter information
2/5
Suspicious content matched by YARA rules
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
A monitored process crashed
1/5
Reads system data
Spyware
f4rsecurity(1).exe
2026-10-08T17:36:06.996
malicious
Windows Exe (x86-64)
Close
f4rsecurity(1).exe
malicious
SHA256:
d238ddba9ab57e60285609242f4d90acf74e7d61492e403ec1a1349deae3665f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Queries a host's domain name
2/5
Delays execution
2/5
Sets up server that accepts incoming connections
1/5
Resolves API functions dynamically
1/5
Tries to detect debugger
1/5
Connects to remote host
1/5
Tries to detect application sandbox
1/5
Downloads file
1/5
Reads system data
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Unusual large memory allocation
Downloader
Hacktool