Threat Feed
2df08b445585f5db43736868b4bc8428.exe
2026-09-14T03:08:58.620
malicious
Windows Exe (x86-32)
Close
2df08b445585f5db43736868b4bc8428.exe
malicious
SHA256:
08f2c963906b126c0a10b47aa28eccebf8e209f3885c54489f771e948dc89b1a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
ValleyRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Enables process privileges
1/5
Modifies operating system directory
1/5
Queries system time
1/5
Performs DNS request
Backdoor
Pe4UI3oZz05x3ghy.exe
2026-09-14T02:57:44.716
malicious
Windows Exe (x86-32)
Close
Pe4UI3oZz05x3ghy.exe
malicious
SHA256:
0a8c74e6033cc8252a2f78e4d167fe5c38a9715a496b8b8992cfe9e9c33a3360
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Schedules task
2/5
Delays execution
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Creates an unusually large number of files
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Creates process with hidden window
1/5
Installs system startup script or application
Injector
N5eO9d4nPIal0oXa.exe
2026-09-14T02:57:27.652
malicious
Windows Exe (x86-32)
Close
N5eO9d4nPIal0oXa.exe
malicious
SHA256:
29d89587cf424b7f492fa2cecf8411797a561da443b5d753dc5e64d49b0e729f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Modifies Windows automatic backups
4/5
Disables a crucial system tool
4/5
Modifies Windows Update configuration
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Tries to disable antivirus software
4/5
Writes into the memory of another process
3/5
Disables a crucial system service
3/5
Takes screenshot
3/5
Monitors keyboard input
3/5
Captures clipboard data
3/5
Tries to evade debugger
3/5
Suspicious content matched by YARA rules
3/5
Injects a file into another process
3/5
Modifies system configuration
2/5
Masquerades file extension
2/5
Query OS Information
2/5
Modifies network configuration
2/5
Searches for sensitive FTP data
2/5
Tries to detect analyzer sandbox
2/5
Hides files
2/5
Changes the desktop wallpaper
2/5
Collects hardware properties
2/5
Searches for cryptocurrency wallet locations
2/5
Queries a host's domain name
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
2/5
Network configuration discovery
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive browser data
2/5
Searches for sensitive password manager data
2/5
Creates an unusually large number of processes
1/5
Monitors keyboard input
1/5
Reads from memory of another process
1/5
Modifies operating system directory
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Accesses Microsoft Security Software registry keys
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Executes WMI query
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Enables process privileges
1/5
Creates mutex
Spyware
Ransomware
Injector
8UIKNX6NBtBBGU6j.exe
2026-09-14T02:54:54.616
malicious
Windows Exe (x86-32)
Close
8UIKNX6NBtBBGU6j.exe
malicious
SHA256:
06c6f25f1488666eabd16407d8e9172026117019cd0f0c89e3628d2fb34ebaff
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Deletes user files
5/5
Appends new extensions to many filenames
5/5
Malicious content matched by YARA rules
4/5
Uses a double file extension
4/5
Malicious file detected via reputation
1/5
Creates an unusually large number of files
1/5
Creates a page with write and execute permissions
1/5
Drops PE file
1/5
Modifies application directory
1/5
Changes folder appearance
1/5
Possibly does reconnaissance
1/5
Resolves API functions dynamically
Ransomware
Wiper
nPMqkGHk1BZJxOff.exe
2026-09-14T02:54:45.166
malicious
Windows Exe (x86-32)
Close
nPMqkGHk1BZJxOff.exe
malicious
SHA256:
5b6df208e5ef4ba0516562500b2015c9c655c2c38b516356b2a2efb5baaa7085
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Schedules task
2/5
Delays execution
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Resolves API functions dynamically
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Creates process with hidden window
1/5
Installs system startup script or application
Injector