Threat Feed
NmxzaM27duPJnPwM.exe
2026-09-04T04:25:41.906
malicious
Windows Exe (x86-32)
Close
NmxzaM27duPJnPwM.exe
malicious
SHA256:
39a33fc13236f1694161874ec4752a261df002578061b3b506afcdbab3f77eb5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
5/5
SalatStealer configuration was extracted
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Known malicious mutex name is created
4/5
Creates a Process with redirected Input
4/5
Malicious file detected via reputation
3/5
Monitors user input
3/5
Takes screenshot
2/5
Reads sensitive browser data
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Schedules task
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
1/5
Timestamp manipulation
1/5
Content matched by YARA rules
1/5
Performs DNS request
1/5
Queries system time
1/5
Modifies application directory
1/5
Possibly does reconnaissance
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Reads system data
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Unusual large memory allocation
1/5
Executes dropped PE file
1/5
Resolves API functions dynamically
Spyware
jhQZDrdM8ARlcP1T.exe
2026-09-04T04:24:12.689
malicious
Windows Exe (x86-64)
Close
jhQZDrdM8ARlcP1T.exe
malicious
SHA256:
d80b0fbb27ebdeff85025017d410089474e344c8955a0567af6ab1b91209030b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
Possibly does reconnaissance
1/5
Resolves API functions dynamically
1/5
Creates a page with write and execute permissions
1/5
Creates mutex
1/5
Queries system time
1/5
Modifies application directory
Ransomware
tySlh1xo0RvKqIDh.exe
2026-09-04T04:24:09.446
malicious
Windows Exe (x86-64)
Close
tySlh1xo0RvKqIDh.exe
malicious
SHA256:
541e1e1f41573c5870a983b14c256d9f992974e5f06891256bded9604da97384
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Sets up server that accepts incoming connections
2/5
Searches for sensitive application data
2/5
Reads network adapter information
2/5
Suspicious content matched by YARA rules
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Searches for sensitive browser data
1/5
Possibly does reconnaissance
1/5
Query OS Information
1/5
Query CPU Properties
1/5
Accesses volumes directly
1/5
Enables process privileges
1/5
Queries system time
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Checks external IP address
Spyware
dLHhrO7PphFzDHQd.exe
2026-09-04T04:22:58.215
malicious
Windows Exe (x86-64)
Close
dLHhrO7PphFzDHQd.exe
malicious
SHA256:
c177618ef7076dd34232f5419ca505ba07e5de65a4005c724102c819d6686537
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies Windows Defender configuration
4/5
Blocks network connection to security products
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Tries to detect application sandbox
2/5
Tries to detect a forensic tool
2/5
Schedules task
2/5
Reads network configuration
2/5
Suspicious content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Accesses Microsoft Security Software registry keys
1/5
Modifies operating system directory
1/5
Installs system service
1/5
Queries system time
1/5
Query CPU Properties
1/5
Tries to detect debugger
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
Spyware
Hgs7d4JapvSJtbna.exe
2026-09-04T04:22:04.378
malicious
Windows Exe (x86-32)
Close
Hgs7d4JapvSJtbna.exe
malicious
SHA256:
52f93bed5952e221f8a7702b693b728c20cfd6b1724e5bb4b94e04d4f4479c22
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector