Threat Feed
9tfoNv3YfPZPqcAt.exe
2026-09-15T08:09:43.010
malicious
Windows Exe (x86-32)
Close
9tfoNv3YfPZPqcAt.exe
malicious
SHA256:
88322394c7b1c0815c0515049e28b95adbbcb06976728184c9aadd309619fa9c
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Schedules task
2/5
Delays execution
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Unusual large memory allocation
Injector
rFe9AP3i1MeIBYvm.exe
2026-09-15T08:07:38.071
malicious
Windows Exe (x86-32)
Close
rFe9AP3i1MeIBYvm.exe
malicious
SHA256:
730a1ac9b1db0b3fd8f7b2e1988fe03cd0a7ec6af449024cde3d578de84c53a3
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Installs system service
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector
wTKdFKh0JoO2w2vE.exe
2026-09-15T08:06:17.107
malicious
Windows Exe (x86-32)
Close
wTKdFKh0JoO2w2vE.exe
malicious
SHA256:
3e493f2a7cdc4dec805912d4f339523a983e23848ec9896c2f7b6bbc67e57299
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Schedules task
2/5
Delays execution
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Tries to detect debugger
1/5
Unusual large memory allocation
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
Injector
CVpwgDZnKpG7hSfR.exe
2026-09-15T08:06:07.781
malicious
Windows Exe (x86-32)
Close
CVpwgDZnKpG7hSfR.exe
malicious
SHA256:
dfbf7204baea56c4d2460f3cdb546571cbaa04a4e081069eea578c1bbb979ebb
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Delays execution
2/5
Schedules task
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Tries to detect debugger
1/5
Installs system startup script or application
1/5
Enumerates running processes
1/5
Enables process privileges
Injector
FcwtcJ3PvCvhEyhF.exe
2026-09-15T08:05:15.836
malicious
Windows Exe (x86-32)
Close
FcwtcJ3PvCvhEyhF.exe
malicious
SHA256:
fecda9b945c61b1f4c85cb7776dc965b06fbd81fdd9a4d5721beb846ccd7929a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Modifies Windows automatic backups
4/5
Writes into the memory of another process
4/5
Malicious file detected via reputation
4/5
Tries to disable antivirus software
4/5
Disables a crucial system tool
4/5
Modifies Windows Update configuration
4/5
Malicious content matched by YARA rules
4/5
Bypasses Windows User Account Control (UAC)
4/5
Modifies control flow of another process
3/5
Captures clipboard data
3/5
Injects a file into another process
3/5
Suspicious content matched by YARA rules
3/5
Monitors keyboard input
3/5
Tries to evade debugger
3/5
Takes screenshot
3/5
Modifies system configuration
3/5
Disables a crucial system service
2/5
Tries to detect analyzer sandbox
2/5
Hides files
2/5
Queries a host's domain name
2/5
Collects hardware properties
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Creates an unusually large number of processes
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
2/5
Changes the desktop wallpaper
2/5
Searches for sensitive browser data
2/5
Modifies network configuration
2/5
Searches for sensitive FTP data
2/5
Query OS Information
2/5
Network configuration discovery
2/5
Searches for cryptocurrency wallet locations
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Accesses Microsoft Security Software registry keys
1/5
Reads from memory of another process
1/5
Modifies operating system directory
1/5
Executes WMI query
1/5
Monitors keyboard input
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Enables process privileges
Spyware
Ransomware
Injector