Threat Feed
4eb9878a75fcea821d6a964528e655dcb849f2cdef0d1f081ad5828039321fab.exe
2026-09-24T21:32:42.220
malicious
Windows Exe (x86-64)
Close
4eb9878a75fcea821d6a964528e655dcb849f2cdef0d1f081ad5828039321fab.exe
malicious
SHA256:
4eb9878a75fcea821d6a964528e655dcb849f2cdef0d1f081ad5828039321fab
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Sets up server that accepts incoming connections
2/5
Queries a host's domain name
2/5
Delays execution
2/5
Reads network adapter information
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor
XLGVndUMeeiFWQRL.exe
2026-09-24T21:26:30.764
malicious
Windows Exe (x86-32)
Close
XLGVndUMeeiFWQRL.exe
malicious
SHA256:
9ee2259d306e4249ceb8ffb6e31939458d00852a4ba6c7ad554956bcb364fa78
VMRay Threat Identifiers
Close
Severity
Operation
5/5
XRed configuration was extracted
5/5
Malicious content matched by YARA rules
5/5
Deletes user files
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Office macro uses a file I/O function
3/5
Performs DNS request for known DDNS domain
2/5
Office macro uses a network function
2/5
Searches for sensitive password manager data
2/5
Executes dropped PE masquerading Filename
2/5
Suspicious content matched by YARA rules
2/5
Delays execution
2/5
Office macro uses an execute function
2/5
Office macro uses a suspicious function
2/5
Searches for sensitive remote access configuration data
2/5
Sets up server that accepts incoming connections
1/5
Installs system startup script or application
1/5
Monitors keyboard input
1/5
Creates mutex
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Contains suspicious Office macro
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Query OS Information
1/5
Checks Internet connection
1/5
Reads mouse position
Backdoor
Wiper
wnq1zGzuHnn0cvye.exe
2026-09-24T21:25:37.831
malicious
Windows Exe (x86-32)
Close
wnq1zGzuHnn0cvye.exe
malicious
SHA256:
0ba5f4fe4429f127615dc61591082edf5b272aa44b010393362881688685fb67
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Searches for sensitive browser data
2/5
Delays execution
2/5
Schedules task
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Enumerates running processes
1/5
Tries to detect debugger
1/5
Installs system startup script or application
1/5
Enables process privileges
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
Injector
7Uw3tbaQrv8RmiP3.exe
2026-09-24T21:21:54.962
malicious
Windows Exe (x86-32)
Close
7Uw3tbaQrv8RmiP3.exe
malicious
SHA256:
0ff479682308fd54747300ac7a05f7fe443281fa710bcd1dbf665f9fcde83742
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
2/5
Schedules task
2/5
Delays execution
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Enables process privileges
1/5
Tries to detect debugger
1/5
Installs system service
1/5
Enumerates running processes
Injector
cOKUzP0rJpkctEul.exe
2026-09-24T21:21:40.923
malicious
Windows Exe (x86-32)
Close
cOKUzP0rJpkctEul.exe
malicious
SHA256:
da2e4c563b3476274244ed3037c97503ef93475eb69f958c8eb6b2eda8f52992
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector