Threat Feed
IN5fjdqYt6fNTcIZ.exe
2026-08-03T19:27:52.832
malicious
Windows Exe (x86-32)
Close
IN5fjdqYt6fNTcIZ.exe
malicious
SHA256:
4a6cb4cd9b40f737f2017436d32d9102f12583f8c544a3076c3721a6d40c2fd1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
2/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Hacktool
vnAiRH2RgSAuorXL.exe
2026-08-03T19:25:59.253
malicious
Windows Exe (x86-32)
Close
vnAiRH2RgSAuorXL.exe
malicious
SHA256:
ac03df211034d1551eac237fd18f4f81f2cfeca18485fa9a38b0a334b7296cb8
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Reads mouse position
1/5
Creates mutex
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Drops PE file
1/5
Creates a page with write and execute permissions
1/5
Executes dropped PE file
Hacktool
hZLCsULWXQNxAZeI.exe
2026-08-03T19:25:42.029
malicious
Windows Exe (x86-32)
Close
hZLCsULWXQNxAZeI.exe
malicious
SHA256:
2f77922488e467cc9047ebf6e7b577cda8db5b976d763891a7027c4c559a59bf
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Captures clipboard data
3/5
Tries to detect the presence of antivirus software
3/5
Reads installed applications
3/5
Suspicious file detected via reputation
3/5
Executable modifies its own file
3/5
Takes screenshot
3/5
Uses HTTP to upload a large amount of data
2/5
Tries to detect virtual machine
2/5
Tries to detect analyzer sandbox
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
2/5
Delays execution
2/5
Query Firmware Information
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Deletes file after execution
2/5
Tries to detect application sandbox
2/5
Disables a system tool
2/5
Queries OS info via WMI
1/5
Drops PE file
1/5
Creates process with hidden window
1/5
Unusual large memory allocation
1/5
Installs system startup script or application
1/5
Modifies operating system directory
1/5
Creates a page with write and execute permissions
1/5
Creates mutex
1/5
Query OS Information
1/5
Accesses volumes directly
1/5
Modifies application directory
1/5
Installs system service
1/5
Enumerates running processes
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
Spyware
VATN0.20260729212103.IMG.iso
2026-08-03T18:51:03.579
malicious
Windows Exe (x86-32)
Close
VATN0.20260729212103.IMG.iso
malicious
SHA256:
5232fe31c50aa3891143a8b12264d316779b2650dc285d4593f6d44da048f957
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
ValleyRAT configuration was extracted
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Delays execution
2/5
Enables critical process privileges
2/5
Schedules task
1/5
Query OS Information
1/5
Collects hardware properties
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Checks external IP address
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Writes an unusually large amount of data to the registry
1/5
Creates process with hidden window
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Enables process privileges
1/5
Kills process
1/5
Enumerates running processes
Backdoor
Vat.N0.20260803122837.IMG.iso
2026-08-03T18:39:57.485
malicious
Windows Exe (x86-32)
Close
Vat.N0.20260803122837.IMG.iso
malicious
SHA256:
2ffbb43a3cc95b2f03f01a3588392a001aed9b9fbae97e455d258bf54fd56cff
VMRay Threat Identifiers
Close
Severity
Operation
5/5
ValleyRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
3/5
Tries to evade debugger
2/5
Schedules task
2/5
Enables critical process privileges
2/5
Delays execution
1/5
Resolves API functions dynamically
1/5
Tries to connect using an uncommon port
1/5
Connects to remote host
1/5
Performs DNS request
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Writes an unusually large amount of data to the registry
1/5
Enables process privileges
1/5
Reads from memory of another process
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Query OS Information
1/5
Collects hardware properties
1/5
Kills process
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Accesses volumes directly
1/5
Content matched by YARA rules
1/5
Checks external IP address
Backdoor