Threat Feed
LzQfeIrNJy7Btgr5.exe
2026-10-09T21:34:39.083
malicious
Windows Exe (x86-32)
Close
LzQfeIrNJy7Btgr5.exe
malicious
SHA256:
d10f90817458d46a2c9f9088962ee4b1216c325c98b000b6e684d4b2d181b3b5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
All network connection attempts failed
3/5
Uses HTTP to upload a large amount of data
3/5
Obscures a file's origin
2/5
Disables a system tool
1/5
Modifies operating system directory
1/5
Reads system data
1/5
Installs system service
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Tries to connect using an uncommon port
Downloader
GCwpBl5kT8ISyIdJ.exe
2026-10-09T21:31:47.556
malicious
Windows Exe (x86-32)
Close
GCwpBl5kT8ISyIdJ.exe
malicious
SHA256:
2baeb0d844d862959f044269811f49012e6fa62469d35c281e1d760232958635
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Modifies Windows automatic backups
4/5
Disables a crucial system tool
4/5
Creates elevated child process
4/5
Bypasses Windows User Account Control (UAC)
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Tries to disable antivirus software
4/5
Modifies Windows Update configuration
3/5
Captures clipboard data
3/5
Disables a crucial system service
3/5
Monitors keyboard input
3/5
Takes screenshot
3/5
Modifies system configuration
3/5
Suspicious content matched by YARA rules
3/5
Injects a file into another process
2/5
Changes the desktop wallpaper
2/5
Modifies network configuration
2/5
Queries a host's domain name
2/5
Searches for sensitive browser data
2/5
Schedules task
2/5
Hides files
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive remote access configuration data
2/5
Query OS Information
1/5
Enables process privileges
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Query OS Information
1/5
Modifies operating system directory
1/5
Executes WMI query
1/5
Enumerates running processes
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Peripheral Device Discovery
1/5
Queries system time
1/5
Reads from memory of another process
1/5
Performs DNS request
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Monitors keyboard input
Spyware
Ransomware
Injector
hUqn7D7a0Gyl77sD.exe
2026-10-09T21:31:10.307
malicious
Windows Exe (x86-64)
Close
hUqn7D7a0Gyl77sD.exe
malicious
SHA256:
e70cf1b080588afb105bd57762845a72c2e826d56d669dc960e1e8edc984f590
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
1/5
Queries system time
1/5
Performs DNS request
1/5
Modifies application directory
1/5
Creates mutex
1/5
Enumerates running processes
Hacktool
F16dHKJLnebSyQ8w.exe
2026-10-09T21:30:50.508
malicious
Windows Exe (x86-64)
Close
F16dHKJLnebSyQ8w.exe
malicious
SHA256:
41f715ce490083c44fb1167c3b8592a9ad97b563997fabb79f8eb66975c57544
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Reads sensitive browser data
2/5
Tries to detect virtual machine
2/5
Searches for sensitive browser data
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
A monitored process crashed
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Reads system data
1/5
Modifies application directory
1/5
Creates a page with write and execute permissions
1/5
Tries to detect debugger
1/5
Possibly does reconnaissance
1/5
Queries system time
Ransomware
xkVxvhT3RiisbXev.exe
2026-10-09T21:30:07.164
malicious
Windows Exe (x86-32)
Close
xkVxvhT3RiisbXev.exe
malicious
SHA256:
4699536547c68f9324b5011d00e4b1a207597446065b08d2d32ff66cfb10509c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Uses HTTP to upload a large amount of data
3/5
Obscures a file's origin
2/5
Disables a system tool
1/5
Query OS Information
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Modifies operating system directory
1/5
Installs system service
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Reads system data
Downloader