Threat Feed
file.exe
2026-07-29T19:41:27.758
malicious
Windows Exe (x86-32)
Close
file.exe
malicious
SHA256:
ebd140217102e211a74b341198292a392a0e25ecf5ec1a53fb411c14c3b7b6f8
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Phorpiex configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Obscures a file's origin
3/5
Connects to lots of SMTP servers
3/5
Tries to open an unusually high number of parallel network connections
2/5
Delays execution
1/5
Checks external IP address
1/5
Queries system time
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Creates mutex
1/5
Content matched by YARA rules
Worm
file.exe
2026-07-29T19:38:14.553
malicious
Windows Exe (x86-32)
Close
file.exe
malicious
SHA256:
d664021eff6b92368479a4b9401272f9f869bddb0a22da5434747bb0433fff45
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Phorpiex configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Downloads file containing email credentials
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Obscures a file's origin
3/5
Tries to open an unusually high number of parallel network connections
3/5
Connects to lots of SMTP servers
3/5
Suspicious host or URL detected via reputation
2/5
Delays execution
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Checks external IP address
1/5
Creates mutex
Worm
QuickFetch.exe
2026-07-29T19:37:11.422
malicious
Windows Exe (x86-64)
Close
QuickFetch.exe
malicious
SHA256:
5459c708a6b6a6bfbbc7e28b668fcbb1a18138abb758244fa15d74d3216dfa3a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Captures clipboard data
3/5
Uses HTTP to upload a large amount of data
3/5
Takes screenshot
3/5
Tries to detect the presence of antivirus software
2/5
Queries OS info via WMI
2/5
Delays execution
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Query Firmware Information
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
1/5
Tries to connect using an uncommon port
Spyware
Z7Oi1BYa4QKIjW64.exe
2026-07-29T19:26:51.829
malicious
Windows Exe (x86-32)
Close
Z7Oi1BYa4QKIjW64.exe
malicious
SHA256:
03d2e8ef968a70c032ffb01c98b29ab612ae48043b44e63d15c2504f7f85de13
VMRay Threat Identifiers
Close
Severity
Operation
5/5
njRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Tries to detect the presence of antivirus software
2/5
Queries OS info via WMI
2/5
Modifies Windows Firewall configuration
1/5
Query OS Information
1/5
Enables process privileges
1/5
Creates mutex
1/5
Monitors keyboard input
1/5
Creates process with hidden window
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Obfuscates control flow
1/5
Resolves API functions dynamically
1/5
Installs system startup script or application
Backdoor
Xenor-v1.exe
2026-07-29T19:26:24.838
malicious
Windows Exe (x86-32)
Close
Xenor-v1.exe
malicious
SHA256:
af9b05c7311f0f4049467a64bb1484b2264955faf61b19e8974757802f197177
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows configuration discovery
5/5
Tries to read cached credentials of various applications
5/5
Known malicious mutex name is created
5/5
SalatStealer configuration was extracted
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Reads sensitive browser data
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Schedules task
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
1/5
Executes dropped PE file
1/5
Performs DNS request
1/5
Timestamp manipulation
1/5
Queries system time
1/5
Reads system data
1/5
Modifies application directory
1/5
Creates process with hidden window
1/5
Possibly does reconnaissance
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Content matched by YARA rules
1/5
Drops PE file
1/5
Unusual large memory allocation
Spyware