Threat Feed
m90C6IrvMqbA6hzB.exe
2026-08-29T04:28:12.393
malicious
Windows Exe (x86-64)
Close
m90C6IrvMqbA6hzB.exe
malicious
SHA256:
1a3e322687223496576fc2c5d7cc47e35712bc98526f19294e8a71b0b42aea36
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
A monitored process crashed
1/5
Resolves API functions dynamically
1/5
Modifies application directory
1/5
Creates a page with write and execute permissions
Ransomware
myoSHv8IK6v11GBS.exe
2026-08-29T04:25:00.133
malicious
Windows Exe (x86-64)
Close
myoSHv8IK6v11GBS.exe
malicious
SHA256:
d81fad40f39732c701593e9132e793e12272384cea7feb0eba8f1ce91a66844a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Uses HTTP to upload a large amount of data
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
3/5
Captures clipboard data
2/5
Query Firmware Information
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Signed executable failed signature validation
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Queries a host's domain name
1/5
Tries to detect application sandbox
1/5
Resolves API functions dynamically
1/5
URL contains a TLD highly associated with phishing
1/5
Unusual large memory allocation
1/5
Tries to connect using an uncommon port
Spyware
8yBF8Rs7TBkIK33Y.exe
2026-08-29T04:23:45.929
malicious
Windows Exe (x86-64)
Close
8yBF8Rs7TBkIK33Y.exe
malicious
SHA256:
788b85c486d8a4d3079b4b2ebf43368a680586a15a03719af8617c59281c6e87
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Monitors clipboard content
4/5
Modifies Windows Defender configuration
2/5
Sets up server that accepts incoming connections
2/5
Reads network adapter information
2/5
Delays execution
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Modifies operating system directory
1/5
Unusual large memory allocation
1/5
Installs system startup script or application
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Accesses Microsoft Security Software registry keys
1/5
Performs DNS request
1/5
Connects to remote host
Keylogger
398da2e951f8287d6aa7e53c1c9c0748a5c39af3353b8af94020036fcb9d5bef.exe
2026-08-29T04:21:52.053
malicious
Windows Exe (x86-64)
Close
398da2e951f8287d6aa7e53c1c9c0748a5c39af3353b8af94020036fcb9d5bef.exe
malicious
SHA256:
398da2e951f8287d6aa7e53c1c9c0748a5c39af3353b8af94020036fcb9d5bef
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Tries to detect virtual machine
2/5
Dead Drop Resolver
1/5
Query OS Information
1/5
Query CPU Properties
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Queries system time
1/5
Tries to detect application sandbox
Spyware
N5xlITNvF6tG3pUJ.exe
2026-08-29T04:20:59.260
malicious
Windows Exe (x86-32)
Close
N5xlITNvF6tG3pUJ.exe
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
2/5
Allows invalid SSL certificates
2/5
Enables critical process privileges
1/5
Installs system service
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Enables process privileges
1/5
Executes dropped PE file
1/5
Enumerates running processes
1/5
Modifies operating system directory
1/5
Creates mutex
1/5
Queries system time
Ransomware